CVE-2014-5772
govhk government_bookstore: Sicherheitsluecke
noneEPSS 0.3%
Description
The Government Bookstore (aka hksarg.isd.sop.govbookstore) application 1.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Source: cvelistv5NVD (NIST)
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
govhkgovernment_bookstore
Metrics
Show all metrics
Severity
none
3.24
no public PoC known
Published
2014-09-09 10:00 UTC