CVE-2014-5615: Medium severity Snapone Snap Secure Android vulnerability
The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5615?
CVE-2014-5615 has been classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-5615?
To fix CVE-2014-5615, update the Snap Secure application to the latest version that includes proper verification of X.509 certificates.
What platforms are affected by CVE-2014-5615?
CVE-2014-5615 specifically affects the Android version 9.5 of the Snap Secure application.
What kind of attack can exploit CVE-2014-5615?
CVE-2014-5615 can be exploited through man-in-the-middle attacks, enabling attackers to spoof servers.
What type of information can be compromised by CVE-2014-5615?
Sensitive information such as login credentials and personal data can be compromised due to the lack of proper SSL certificate verification in CVE-2014-5615.