CVE-2012-2993

MEDIUM

Microsoft Windows Phone 7 - SSL Man-in-the-Middle

Title source: llm

Description

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.

Scores

CVSS v3 5.9
EPSS 0.1469
EPSS Percentile 94.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-295
Status draft

Affected Products (1)

microsoft/windows_phone_7_firmware

Timeline

Published Sep 18, 2012
Tracked Since Feb 18, 2026