Boletines de Vulnerabilidades

Cisco Spark Mobile Application Man-in-the-Middle Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the Cisco Spark mobile application could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the affected device.The vulnerability is due to improper validation of the SSL certificate used to manage the device. An attacker could exploit this vulnerability by using the default SSL certificate to view sensitive information.Cisco has confirmed the vulnerability; however, software updates are not available.Although a successful exploit could be

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150922-CVE-2015-6303?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Spark%20Mobile%20Application%20Man-in-the-Middle%20Vulnerabi

Identificadores estándar

Propiedad Valor
CVE

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-10-08

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT