VulnerabilityModified
CVE-2008-1938
Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain sensitive information and conduct spoofing attacks.
MEDIUM 6.4EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain sensitive information and conduct spoofing attacks.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- sony/mylo com 2
- Source
- cve@mitre.org
References
- http://esupport.sony.com/perl/news-item.pl?news_id=262&mdl=COM2
- http://jvn.jp/jp/JVN%2376788395/index.html
- http://mylo.nccl.sony.co.jp/download/M-W002-001-02/index.html
- http://mylo.nccl.sony.co.jp/hotnews/2008/04/01/index.html
- http://secunia.com/advisories/29928Vendor Advisory
- http://www.securityfocus.com/bid/28905
- http://www.vupen.com/english/advisories/2008/1349/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41971
- http://esupport.sony.com/perl/news-item.pl?news_id=262&mdl=COM2
- http://jvn.jp/jp/JVN%2376788395/index.html
- http://mylo.nccl.sony.co.jp/download/M-W002-001-02/index.html
- http://mylo.nccl.sony.co.jp/hotnews/2008/04/01/index.html
- http://secunia.com/advisories/29928Vendor Advisory
- http://www.securityfocus.com/bid/28905
- http://www.vupen.com/english/advisories/2008/1349/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41971
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.