Certificate Authority Validation Flaw in Cisco IronPort Web Security Appliance
CVE-2012-1326
7.4HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 15 January 2020
Summary
The Cisco IronPort Web Security Appliance versions up to and including 7.5 contains a vulnerability where it fails to properly validate the basic constraints of the certificate authority. This flaw can be exploited by attackers to perform man-in-the-middle (MITM) attacks, leading to potential interception of sensitive data and unauthorized access to network resources. Organizations utilizing this appliance are advised to implement mitigation strategies and update to the latest version to safeguard against these risks.
Affected Version(s)
IronPort Web Security Appliance <= 7.5
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved