Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-4288

Опубликовано: 29 июл. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs CSCuo29561, CSCuv40466, and CSCuv40470.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:cisco:web_security_appliance:8.5.0-000:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:h:cisco:email_security_appliance:8.5.7-042:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:h:cisco:content_security_management_appliance:8.3.6-048:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00137
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs CSCuo29561, CSCuv40466, and CSCuv40470.

EPSS

Процентиль: 34%
0.00137
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310