Man-in-the-Middle Vulnerability in kantan netprint App for iOS
CVE-2020-5521
7.4HIGH
What is CVE-2020-5521?
The kantan netprint application for iOS, specifically versions up to 2.0.2, is susceptible to exploitation due to a lack of X.509 certificate verification. This vulnerability enables potential attackers to perform man-in-the-middle attacks, allowing them to impersonate servers and intercept sensitive information by utilizing a maliciously crafted certificate. Users of the app should be aware of this security weakness and consider updating to versions that address this critical flaw.
Affected Version(s)
kantan netprint App for iOS 2.0.2 and earlier
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved