VULNERABILITY INTELLIGENCE

CVE-2002-2125

CVSS score6.4 NONE
EPSS probability8.26%
CISA KEVNot currently listed
Published2002-12-31
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:P/I:P/A:N

Description

Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.

Weakness classification

  • nvd@nist.gov: NVD-CWE-Other

Primary references