HIGH · 7.8

CVE-2008-1113

Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed ...

Vulnerability Description

Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Cisco7921 Wireless Ip PhoneAll versions
Vocera CommunicationsVocera Communications BadgeAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-1113?

CVE-2008-1113 is a vulnerability with a CVSS score of 7.8 (HIGH). Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed ...

How severe is CVE-2008-1113?

CVE-2008-1113 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1113?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco 7921 Wireless Ip Phone, Vocera Communications Vocera Communications Badge.