PT-2008-2709 · Cisco · Cisco Unified Wireless Ip Phone 7921

George Ou

·

Published

2008-03-03

·

Updated

2008-09-05

·

CVE-2008-1113

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Wireless IP Phone 7921 (affected versions not specified)
Description The issue concerns a problem with the validation of server certificates when using Protected Extensible Authentication Protocol (PEAP). This allows remote wireless access points to intercept hashed passwords and perform man-in-the-middle (MITM) attacks.
Recommendations For Cisco Unified Wireless IP Phone 7921, consider disabling the use of Protected Extensible Authentication Protocol (PEAP) until a patch is available to properly validate server certificates. Restrict access to wireless networks to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1113

Affected Products

Cisco Unified Wireless Ip Phone 7921