Insecure Certificate Validation in Audible for Android Affects Adobe SDKs
CVE-2019-11554

5.9MEDIUM

Key Information:

Vendor

Amazon

Status
Vendor
CVE Published:
6 December 2019

What is CVE-2019-11554?

The Audible application for Android, up to version 2.34.0, has a vulnerability due to inadequate SSL certificate validation within Adobe SDKs. This weakness enables attackers to exploit man-in-the-middle (MITM) scenarios, potentially resulting in unauthorized access or denial of service. Users are strongly advised to update their applications and implement security best practices to guard against these types of threats.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.