MITM Vulnerability in Cisco IronPort Web Security Appliance
CVE-2012-1316

5.9MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 January 2020

Summary

The Cisco IronPort Web Security Appliance lacks proper verification of certificate revocation. This oversight can potentially expose users to man-in-the-middle (MITM) attacks, allowing malicious actors to intercept and alter sensitive communications without detection. Ensuring that certificate statuses are correctly validated is crucial for maintaining the integrity and confidentiality of data exchanged over secure connections.

Affected Version(s)

IronPort Web Security Appliance through at least 2012-04-11

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.