CVE-2012-2993

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:o:microsoft:windows_phone:7:*:*:*:*:*:*:*

Information

Published : 2012-09-17 20:48

Updated : 2017-08-28 18:31


NVD link : CVE-2012-2993

Mitre link : CVE-2012-2993


JSON object : View

CWE
CWE-310

Cryptographic Issues

Advertisement

dedicated server usa

Products Affected

microsoft

  • windows_phone