« Volver al listado

CVE-2010-4211

Estado: ModificadaBaja (2.9)—

The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-4211",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.9,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-11-09T01:00:02.697",
  "references": [
    {
      "url": "http://itunes.apple.com/us/app/paypal/id283646709",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://news.cnet.com/8301-27080_3-20021730-245.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://online.wsj.com/article/SB10001424052748703506904575592782874885808.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://viaforensics.com/press-releases/viaforensics-uncovers-paypal-application-vulnerability.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://viaforensics.com/security/viaforensics-uncovers-significant-vulnerability-paypal-iphone.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/44657",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/2887",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/63002",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://itunes.apple.com/us/app/paypal/id283646709",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://news.cnet.com/8301-27080_3-20021730-245.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://online.wsj.com/article/SB10001424052748703506904575592782874885808.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://viaforensics.com/press-releases/viaforensics-uncovers-paypal-application-vulnerability.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://viaforensics.com/security/viaforensics-uncovers-significant-vulnerability-paypal-iphone.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/44657",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/2887",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/63002",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate."
    },
    {
      "lang": "es",
      "value": "La aplicación de PayPal anterior a v3.0.1 de IOS no comprueba que el nombre del servidor coincide con el nombre de dominio del sujeto de un certificado X.509, que permite a los atacantes \"man-in-the-middle\"  falsificar un servidor web de PayPal a través de un certificado de su elección."
    }
  ],
  "lastModified": "2026-06-16T23:24:22.080",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ebay:paypal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B5F87AC-4F63-4FEB-A926-DAC25C760F6F",
              "versionEndIncluding": "3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:3.1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "51D3BE2B-5A01-4AD4-A436-0056B50A535D"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:3.1.2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A20F171-79FE-43B9-8309-B18341639FA1"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:3.1.3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "126EF22D-29BC-4366-97BC-B261311E6251"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}