VULNERABILITY INTELLIGENCE
CVE-2002-2125
CVSS score6.4 NONE
EPSS probability8.26%
CISA KEVNot currently listed
Published2002-12-31
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Description
Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.
Weakness classification
- nvd@nist.gov: NVD-CWE-Other