CVE-2015-6303: Infoleak
The Cisco Spark application 2015-07-04 for mobile operating systems does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs CSCut36742 and CSCut36844.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6303?
CVE-2015-6303 is considered a high severity vulnerability due to its potential to allow man-in-the-middle attacks.
How do I fix CVE-2015-6303?
To mitigate CVE-2015-6303, upgrade to a Cisco Spark version that properly verifies X.509 certificates.
What types of attacks can CVE-2015-6303 allow?
CVE-2015-6303 can allow man-in-the-middle attackers to spoof servers and obtain sensitive information.
Which version of Cisco Spark is affected by CVE-2015-6303?
CVE-2015-6303 affects Cisco Spark version 2015-07-04_base.
What is the root cause of CVE-2015-6303?
CVE-2015-6303 is caused by improper verification of X.509 certificates from SSL servers.