Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q94c-7f46-5326

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.

EPSS

Процентиль: 94%
0.1469
Средний

5.9 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.9
nvd
больше 13 лет назад

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.

EPSS

Процентиль: 94%
0.1469
Средний

5.9 Medium

CVSS3

Дефекты

CWE-295