CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Wap_gateway | Cmg | * | * |