PT-2015-7234 · Cisco · Cisco Jabber

Publicado

2015-12-26

·

Atualizado

2016-12-07

·

CVE-2015-6409

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Jabber versions 10.6.x through 11.1.x
Description The issue allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks, triggering cleartext XMPP sessions.
Recommendations For versions 10.6.x through 11.1.x, consider disabling the STARTTLS functionality as a temporary workaround until a patch is available. Restrict access to the XMPP sessions to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6409

Produtos afetados

Cisco Jabber