ID

VAR-E-201109-0609


TITLE

Pantech Link Phones Browser Certificate Verification Security Weakness

Trust: 0.3

sources: BID: 49755

DESCRIPTION

The browser of Pantech Link Phones is prone to a security weakness because it fails to verify SSL certificates presented by a remote server.
An attacker can exploit this weakness to masquerade as a legitimate server using a man-in-the-middle attack or to launch other attacks, such as phishing.

Trust: 0.3

sources: BID: 49755

AFFECTED PRODUCTS

vendor:pantechmodel:link p7040pscope:eqversion:0

Trust: 0.3

sources: BID: 49755

EXPLOIT

An attacker use readily available tools to carry out this attack.

Trust: 0.3

sources: BID: 49755

PRICE

Free

Trust: 0.3

sources: BID: 49755

TYPE

Design Error

Trust: 0.3

sources: BID: 49755

CREDITS

Trustwave

Trust: 0.3

sources: BID: 49755

EXTERNAL IDS

db:BIDid:49755

Trust: 0.3

sources: BID: 49755

REFERENCES

url:https://www.trustwave.com/spiderlabs/advisories/twsl2011-014.txt

Trust: 0.3

url:http://www.pantechusa.com/phones/link

Trust: 0.3

sources: BID: 49755

SOURCES

db:BIDid:49755

LAST UPDATE DATE

2022-07-27T09:50:04.270000+00:00


SOURCES UPDATE DATE

db:BIDid:49755date:2011-09-23T00:00:00

SOURCES RELEASE DATE

db:BIDid:49755date:2011-09-23T00:00:00