CVE-2018-12499

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
02/07/2018
Last modified:
07/09/2018

Description

The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was downloading what appeared to be a client certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:motorola:mbp853_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mbp853:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools