Security Advisory

CVE-2015-6303

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2015-09-24 14:00:00
Last updated 2024-08-06 07:15:13
Assigner cisco
State PUBLISHED

Description

The Cisco Spark application 2015-07-04 for mobile operating systems does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs CSCut36742 and CSCut36844.