CVE-2014-5872: Medium severity safenet mobilepass vulnerability
The SafeNetMobile Pass (aka securecomputing.devices.android.controller) application 8.3.7.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5872?
CVE-2014-5872 is classified as a high severity vulnerability due to its potential for exploitation through man-in-the-middle attacks.
How do I fix CVE-2014-5872?
To fix CVE-2014-5872, update the SafeNetMobile Pass application to a version that properly verifies X.509 certificates from SSL servers.
Who is affected by CVE-2014-5872?
CVE-2014-5872 affects users of the SafeNetMobile Pass application version 8.3.7.11 on Android devices.
What type of attack does CVE-2014-5872 facilitate?
CVE-2014-5872 facilitates man-in-the-middle attacks that can allow attackers to spoof SSL servers.
What kind of information can be compromised due to CVE-2014-5872?
Due to CVE-2014-5872, an attacker could obtain sensitive information from users by exploiting the lack of certificate validation.