CVE-2012-5792 describes a critical vulnerability in the Sage Pay Direct module for osCommerce, where the module fails to validate the server hostname against the X.509 certificate's Common Name or subjectAltName field. This oversight enables man-in-the-middle (MitM) attackers to spoof SSL servers using any valid certificate, potentially compromising sensitive data. With a CVSS score of 5.8, this vulnerability is of medium severity, requiring moderate attack complexity but allowing for partial confidentiality and integrity impact without authentication. Despite its potential, there is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:oscommerce:oscommerce:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:sagepay:sage_pay_direct_module:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.