Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco Jabber for Windows 证书验证安全绕过漏洞
Vulnerability Description
Cisco Jabber for Windows是美国思科(Cisco)公司的一套用于Windows平台的统一通信客户端解决方案。该方案提供了在线状态显示、即时消息、语音等功能。 Windows平台上的Cisco Jabber中存在证书验证漏洞,该漏洞源于程序没有验证SSL服务器端的X.509证书。中间人攻击者可借助特制的证书利用该漏洞欺骗服务器,并修改客户端服务器数据流。
CVSS Information
N/A
Vulnerability Type
N/A