CVE

Id
31230  
CVE No.
CVE-2008-1113  
Status
Candidate  
Description
Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.  
Phase
Assigned (20080303)  
Votes
None (candidate not yet proposed)  
Comments