CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wap_gateway | Cmg | * | * |