Improper SSL Certificate Validation in Coles Credit Card Application for Android
CVE-2014-5562

Currently unrated

Key Information:

Vendor
CVE Published:
9 September 2014

What is CVE-2014-5562?

The Coles Credit Card App for Android fails to adequately verify X.509 certificates from SSL servers. This security oversight allows man-in-the-middle attackers to masquerade as legitimate servers. Exploiting this vulnerability, attackers can intercept sensitive information transmitted between users and the app, leading to potential data breaches. Users of the application should ensure they are using the latest version to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.