SSL Certificate Validation Flaw in Active 24 for Android by Zentity
CVE-2014-6808

Currently unrated

Key Information:

Status
Vendor
CVE Published:
30 September 2014

What is CVE-2014-6808?

The Active 24 application version 1.0.1 for Android fails to validate X.509 SSL certificates properly, leaving users susceptible to man-in-the-middle attacks. This allows malicious actors to spoof legitimate servers and intercept sensitive data through the use of crafted certificates, posing a significant risk to user privacy and security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.