CVE-2014-6637: Medium severity facebook vulnerability
The Facebook Facts (aka com.wFacebookFacts) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6637?
CVE-2014-6637 is considered a critical vulnerability as it allows man-in-the-middle attackers to intercept sensitive information.
How does CVE-2014-6637 exploit vulnerabilities in the Facebook Facts app?
CVE-2014-6637 exploits the lack of X.509 certificate verification in the Facebook Facts app, enabling authentication bypass.
How do I mitigate the risk associated with CVE-2014-6637?
To mitigate CVE-2014-6637, uninstall the affected version of the Facebook Facts app and avoid using untrusted networks.
Are there any patches available for CVE-2014-6637?
No patches are available for CVE-2014-6637; the recommended action is to uninstall the vulnerable app.
What type of attacks can CVE-2014-6637 lead to?
CVE-2014-6637 can lead to man-in-the-middle attacks, where attackers can spoof servers and intercept sensitive user data.