The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was downloading what appeared to be a client certificate.
References
Link | Resource |
---|---|
https://blog.sean-wright.com/cve-2018-12499/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2018-07-02T16:00:00
Updated: 2018-07-02T15:57:01
Reserved: 2018-06-16T00:00:00
Link: CVE-2018-12499
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-07-02T16:29:00.303
Modified: 2018-09-07T16:33:51.017
Link: CVE-2018-12499
JSON object: View
Redhat Information
No data.
CWE