CVE-2018-12499
 
Severity Score
7.4
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was downloading what appeared to be a client certificate.
El firmware de Motorola MBP853 no valida correctamente los certificados del servidor. Esto permite un ataque Man-in-the-Middle (MitM) entre una cámara Motorola MBP853 y los servidores con los que se comunica. En una de estas instancias, se identificó que el dispositivo descargaba lo que parecía ser un certificado de cliente.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-06-16 CVE Reserved
- 2018-07-02 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://blog.sean-wright.com/cve-2018-12499 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Motorola Search vendor "Motorola" | Mbp853 Firmware Search vendor "Motorola" for product "Mbp853 Firmware" | - | - |
Affected
| in | Motorola Search vendor "Motorola" | Mbp853 Search vendor "Motorola" for product "Mbp853" | - | - |
Safe
|