CVE-2015-6409
published 2015-12-26CVE-2015-6409: Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions…
PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.34%
68.0th percentile
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | jabber | — | — |
| cisco | jabber_starttls_downgrade | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w4rj-fr95-86j5: Cisco Jabber 10
ghsa_unreviewed·2022-05-17
CVE-2015-6409 [MEDIUM] CWE-200 GHSA-w4rj-fr95-86j5: Cisco Jabber 10
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.
Cisco
Cisco Jabber STARTTLS Downgrade Vulnerability
vendor_cisco·2015-12-24·CVSS 4.3
CVE-2015-6409 [MEDIUM] Cisco Jabber STARTTLS Downgrade Vulnerability
Cisco Jabber STARTTLS Downgrade Vulnerability
A vulnerability in the Cisco Jabber client could allow an unauthenticated, remote attacker to perform a STARTTLS downgrade attack.
The vulnerability exists because the client does not verify that an Extensible Messaging and Presence Protocol (XMPP) connection has been established with Transport Layer Security (TLS). An attacker could exploit this vulnerability by performing a man-in-the-middle attack to tamper with the XMPP connection and avoid TLS negotiation. A successful exploit could allow the attacker to cause the client to establish a cleartext XMPP connection.
Cisco will release software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following
Cisco
Cisco Jabber STARTTLS Downgrade Vulnerability
vendor_cisco
CVE-2015-6409 Cisco Jabber STARTTLS Downgrade Vulnerability
CVE-2015-6409: Cisco Jabber STARTTLS Downgrade Vulnerability
A vulnerability in the Cisco Jabber client could allow an unauthenticated, remote attacker to perform a STARTTLS downgrade attack. The vulnerability exists because the client does not verify that an Extensible Messaging and Presence Protocol (XMPP) connection has been established with Transport Layer Security (TLS). An attacker could exploit this vulnerability by performing a man-in-the-middle attack to tamper with the XMPP connection and avoid TLS negotiation. A successful exploit could allow the attacker to cause the client to establish a cleartext XMPP connection. Cisco will release software updates that address this vulnerability.
Bug IDs: CSCux74848, CSCux74895, CSCux74900, CSCux74848, CSCux74895
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151224-jabhttp://www.securityfocus.com/bid/79678http://www.securitytracker.com/id/1034540http://www.synacktiv.com/ressources/cisco_jabber_starttls_downgrade.pdfhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151224-jabhttp://www.securityfocus.com/bid/79678http://www.securitytracker.com/id/1034540http://www.synacktiv.com/ressources/cisco_jabber_starttls_downgrade.pdf
2015-12-26
Published