CVE-2016-6562 - CVE House
Back to Database
Status published High CVE-2016-6562

ShoreTel Mobility Client for iOS and Android, version 9.1.3.109 and earlier, fails to properly validate SSL certificates provided by HTTPS connections

Vulnerability Description

On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position to perform MITM attacks may be able to obtain sensitive account information such as login credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-6562

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Mobility Client iOS, Mobility Client Andoid
Vulnerable Versions:
9.1.3.109

Timeline

Official Publish: July 13th, 2018
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)