CVE-2016-2268
CVE-2016-2268
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/135617/Dell-SecureWorks-iOS-Certificate-Validation-Failure.htmlhttp://seclists.org/fulldisclosure/2016/Feb/27https://itunes.apple.com/us/app/dell-secureworks/id533072046http://www.info-sec.ca/advisories/Dell-SecureWorks.htmlhttp://www.securityfocus.com/archive/1/537445/100/0/threaded