X.509 Certificate Verification Flaw in Find Color Application for Android
CVE-2014-7023

Currently unrated

Key Information:

Vendor
CVE Published:
16 October 2014

What is CVE-2014-7023?

The Find Color application version 1.1.1 for Android is susceptible to a vulnerability that does not adequately verify X.509 certificates from SSL servers. This oversight enables attackers to execute man-in-the-middle attacks, allowing them to intercept and manipulate data transmitted between the application and the server. As a result, sensitive information may be exposed to unauthorized parties through the use of crafted certificates, posing a significant risk to users' privacy and security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.