Description
The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was downloading what appeared to be a client certificate.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-4469 | The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was downloading what appeared to be a client certificate. |
References
| Link | Providers |
|---|---|
| https://blog.sean-wright.com/cve-2018-12499/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T08:38:06.314Z
Reserved: 2018-06-16T00:00:00.000Z
Link: CVE-2018-12499
No data.
Status : Modified
Published: 2018-07-02T16:29:00.303
Modified: 2024-11-21T03:45:20.460
Link: CVE-2018-12499
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD