ZeroHour

CVE-2017-2110

CVSS 3.0
5.9 medium
EPSS
<1%p49
Published
()
Modified
Description

The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Vendors
nissan securities
Products
access cx
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.