MITM Vulnerability in Cisco IronPort Web Security Appliance
CVE-2012-1316
5.9MEDIUM
Summary
The Cisco IronPort Web Security Appliance lacks proper verification of certificate revocation. This oversight can potentially expose users to man-in-the-middle (MITM) attacks, allowing malicious actors to intercept and alter sensitive communications without detection. Ensuring that certificate statuses are correctly validated is crucial for maintaining the integrity and confidentiality of data exchanged over secure connections.
Affected Version(s)
IronPort Web Security Appliance through at least 2012-04-11
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved