Man-in-the-Middle Vulnerability in PUMATRAC App by PUMA
CVE-2017-8943

5.9MEDIUM

Key Information:

Vendor

Puma

Status
Vendor
CVE Published:
15 May 2017

What is CVE-2017-8943?

The PUMATRAC app for iOS version 3.0.2 does not properly verify X.509 certificates from SSL servers. This oversight enables attackers to execute man-in-the-middle attacks, allowing them to spoof SSL servers and intercept sensitive user information by using a crafted certificate. Users of this app are urged to be cautious as their data may be exposed to malicious entities.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.