CVE-2007-5460: Weak Encryption
Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/Password obtained by (1) sniffing or (2) spoofing the docking process.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5460?
CVE-2007-5460 is considered to have a medium severity due to the weak encryption used for transmitting sensitive information.
How do I fix CVE-2007-5460?
To mitigate CVE-2007-5460, upgrade to a version of Microsoft ActiveSync that employs stronger encryption methods.
Which systems are affected by CVE-2007-5460?
CVE-2007-5460 affects Microsoft ActiveSync 4.1 when used with Windows Mobile 5.0.
What kind of attacks can exploit CVE-2007-5460?
Attackers might exploit CVE-2007-5460 by sniffing USB connections to decode the transmitted PIN or password.
Is CVE-2007-5460 still a threat today?
While CVE-2007-5460 is an older vulnerability, it remains a threat for legacy systems still using these versions.