Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Tsukasa Hamano

Pesquisador deOpen Source Solution Technology Corporation
#44800de 53,638
5.8CVSS total
Vulnerabilidades · 1
PT-2012-3161
5.8
2012-04-27
Ntt Docomo · Sp Mode Mail Application · CVE-2012-1244
**Name of the Vulnerable Software and Affected Versions** NTT DOCOMO sp mode mail application version 5400 and earlier **Description** The issue concerns the NTT DOCOMO sp mode mail application, which fails to properly verify X.509 certificates from SSL servers. This allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. **Recommendations** For version 5400 and earlier, update the application to a version that properly verifies X.509 certificates to prevent man-in-the-middle attacks. As a temporary workaround, consider disabling the use of SSL servers until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.