5.8
CVSSv2

CVE-2013-1651

Published: 05/09/2013 Updated: 05/03/2014
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

OXUpdater in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle malicious users to spoof update servers and install arbitrary software via a crafted certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

open-xchange open-xchange server 6.22.1

open-xchange open-xchange server 6.22.0

open-xchange open-xchange server 6.20.7

Exploits

Multiple security issues for Open-Xchange Server have been discovered and fixed The vendor has chosen responsible full disclosure to publish security issue details Users of the software have already been provided with patched versions Proof regarding authenticity can be obtained from the published release notes: softwareopen-xchangecom ...
Open-Xchange version 6 suffers from cross site scripting, local file inclusion, HTTP header injection / response splitting, missing SSL enforcement, server-side request forging, insecure password hashing, and file permission vulnerabilities ...