PT-2012-5536 · M Link · M-Link

Published

2012-08-25

·

Updated

2012-08-27

·

CVE-2012-4669

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions M-Link versions prior to R14.6v14 M-Link versions prior to R15.1v10
Description The issue allows remote XMPP servers to spoof domains via responses for domains that were not asserted, due to a lack of verification that a request was made for an XMPP Server Dialback response.
Recommendations For versions prior to R14.6v14, update to R14.6v14 or later. For versions prior to R15.1v10, update to R15.1v10 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4669

Affected Products

M-Link