CVE-2012-6399: Input Validation
Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, aka Bug ID CSCud94176.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6399?
CVE-2012-6399 is classified as a high-severity vulnerability due to its potential for exploitation by man-in-the-middle attacks.
How do I fix CVE-2012-6399?
To fix CVE-2012-6399, update Cisco WebEx on iOS to a version that implements proper host verification.
What type of attack does CVE-2012-6399 enable?
CVE-2012-6399 enables man-in-the-middle attacks by allowing an attacker to spoof SSL servers with a valid certificate.
Which version of Cisco WebEx is affected by CVE-2012-6399?
CVE-2012-6399 affects Cisco WebEx version 4.1 on iOS devices.
What is the main issue with CVE-2012-6399?
The main issue with CVE-2012-6399 is that it does not verify server hostname matching for SSL certificates, leading to potential security risks.