X.509 Certificate Validation Flaw in mobiGate App for Android and iOS
CVE-2016-7805

5.9MEDIUM

What is CVE-2016-7805?

The mobiGate App for Android and iOS fails to properly validate X.509 certificates from SSL servers. This vulnerability allows attackers to perform man-in-the-middle attacks, potentially leading to the spoofing of servers. As a result, sensitive information transmitted to and from the app can be intercepted through a maliciously crafted certificate, putting users at significant risk.

Affected Version(s)

mobiGate App for Android version 2.2.1.2 and earlier

mobiGate App for iOS version 2.2.4.1 and earlier

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.