CVE-2013-1651: Medium severity Open-Xchange Open-Xchange Server vulnerability
OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof update servers and install arbitrary software via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1651?
CVE-2013-1651 is classified as a high severity vulnerability due to its potential for exploitation in man-in-the-middle attacks.
How do I fix CVE-2013-1651?
To fix CVE-2013-1651, ensure you upgrade to Open-Xchange Server version 6.20.7 rev14, 6.22.0 rev13, or 6.22.1 rev14 or later.
What impact does CVE-2013-1651 have on my system?
CVE-2013-1651 can allow attackers to spoof update servers and install arbitrary software, posing significant security risks.
Which versions of Open-Xchange Server are affected by CVE-2013-1651?
CVE-2013-1651 affects Open-Xchange Server versions 6.20.7 before rev14, 6.22.0 before rev13, and 6.22.1 before rev14.
Can CVE-2013-1651 be exploited remotely?
Yes, CVE-2013-1651 can be exploited remotely by man-in-the-middle attackers through faulty SSL certificate verification.