CVE-2002-2125

Loading...

General

Score:6.4/10.0
Severity:Medium
Category:N/A

Impact Metrics

Confidentiality:Partial
Integrity:Partial
Availability:None

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Published on 31/12/02 - Updated on 05/09/08

Description

Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.

Category:

There is insufficient information about the issue to classify it; details are unknown or unspecified.

Security Notices

US National Vulnerability DatabaseCVE-2002-2125

Exploits

No exploits available for this CVE in our database.

Relative technologies

VendorProduct
microsoftie

Share this vulnerability with:

Twitter Facebook LinkedIn Mail