Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tsukasa Hamano

Researcher fromOpen Source Solution Technology Corporation
#44760of 53,635
5.8Total CVSS
Vulnerabilities · 1
PT-2012-3161
5.8
2012-04-27
Ntt Docomo · Sp Mode Mail Application · CVE-2012-1244
**Name of the Vulnerable Software and Affected Versions** NTT DOCOMO sp mode mail application version 5400 and earlier **Description** The issue concerns the NTT DOCOMO sp mode mail application, which fails to properly verify X.509 certificates from SSL servers. This allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. **Recommendations** For version 5400 and earlier, update the application to a version that properly verifies X.509 certificates to prevent man-in-the-middle attacks. As a temporary workaround, consider disabling the use of SSL servers until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.