VulnerabilityModified
CVE-2008-1114
Vocera Communications wireless handsets, when using Protected Extensible Authentication Protocol (PEAP), do not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM)…
MEDIUM 4.3EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
Vocera Communications wireless handsets, when using Protected Extensible Authentication Protocol (PEAP), do not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- vocera/wireless handset
- Source
- cve@mitre.org
References
- http://blogs.zdnet.com/security/?p=896
- http://blogs.zdnet.com/security/?p=901
- http://seclists.org/fulldisclosure/2008/Feb/0402.html
- http://www.securityfocus.com/bid/27935
- http://www.vocera.com/downloads/InfrastructureGuide.pdf
- http://blogs.zdnet.com/security/?p=896
- http://blogs.zdnet.com/security/?p=901
- http://seclists.org/fulldisclosure/2008/Feb/0402.html
- http://www.securityfocus.com/bid/27935
- http://www.vocera.com/downloads/InfrastructureGuide.pdf
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.