First published: Tue Sep 09 2014(Updated: )
The IMPI Mobile Security (aka com.impi) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Impi Impi Mobile Security | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5642 is considered a high severity vulnerability due to its potential for man-in-the-middle attacks.
CVE-2014-5642 affects users by allowing attackers to spoof servers and obtain sensitive information through unverified SSL connections.
CVE-2014-5642 specifically affects version 2.1.0 of the IMPI Mobile Security app.
Mitigating the risks associated with CVE-2014-5642 involves updating the IMPI Mobile Security application to a version that verifies X.509 certificates.
There is no specific patch for CVE-2014-5642, but upgrading to a newer version of the app is recommended to eliminate the vulnerability.