Medium severity5.9NVD Advisory· Published Sep 18, 2012· Updated Apr 29, 2026
CVE-2012-2993
CVE-2012-2993
Description
Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.
Affected products
1- cpe:2.3:o:microsoft:windows_phone_7_firmware:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.kb.cert.org/vuls/id/389795nvdThird Party AdvisoryUS Government Resource
- www.securityfocus.com/bid/55569nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/78620nvdThird Party AdvisoryVDB Entry
- osvdb.org/85619nvdBroken Link
News mentions
0No linked articles in our index yet.