search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Verisign transmits sensitive customer information in plain text when applying for a "Code Signing Digital ID"

Vulnerability Note VU#251339

Original Release Date: 2002-05-30 | Last Revised: 2002-06-04

Overview

Verisign offers a service entitled "Code Signing Digital ID for Microsoft Authenticode." Information that is submitted to this site is not transmitted via an SSL secured session, instead it is transmitted in the plain-text.

Description

Verisign offers a service entitled "Code Signing Digital ID for Microsoft Authenticode." A fee is charged for this service, and users can enter their credit card information to sign up. The site states that the information is transmitted via an SSL-secured session, but this does not appear to be the case. The link provided for this service begins with http:// rather than https:// indicating that a non-SSL HTTP session should be used. Therefore the data is transmitted in the plaintext.

Impact

Subscribers to this service may transmit their credit card and other sensitive information over the Internet in plaintext.

Solution

As of May 30, 2002, Verisign has corrected this problem on their web site, and no further user action is necessary.

Change the http:// to https:// and verify that an SSL session has been established with your browser. The appropriate link should be similar to the following:

https://digitalid.verisign.com/cgi-bin/haydn.exe?VHTML_FILE=developer/VSCclass3MSCSie4.htm&originator=$$pOriginator$$

Vendor Information

251339
 

Verisign Affected

Notified:  May 24, 2002 Updated: May 30, 2002

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has confirmed that this problem has been resolved on the server-side as of 5/30/02.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported by Daniel Norton .

This document was written by Jason Rafail.

Other Information

CVE IDs: None
Date Public: 2002-05-18
Date First Published: 2002-05-30
Date Last Updated: 2002-06-04 17:23 UTC
Document Revision: 6

Sponsored by CISA.