CVE-2014-5899: Medium severity accesspress parallax vulnerability
Published Sep 15, 2014
·Updated
The Nespresso (aka com.nespresso.activities) application 2.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Nespresso Nespresso Android=2.4.1
Event History
Sep 15, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5899?
CVE-2014-5899 has a high severity rating due to its potential to allow man-in-the-middle attacks.
2
How do I fix CVE-2014-5899?
To fix CVE-2014-5899, update the Nespresso application to a version that properly verifies X.509 certificates.
3
What type of attack does CVE-2014-5899 make possible?
CVE-2014-5899 allows man-in-the-middle attackers to spoof servers and intercept sensitive information.
4
Which application is affected by CVE-2014-5899?
CVE-2014-5899 affects the Nespresso application version 2.4.1 for Android.
5
What is the impact of not addressing CVE-2014-5899?
Failing to address CVE-2014-5899 can lead to sensitive data exposure and unauthorized access to user information.