CVE-2014-6686: Medium severity zoho books vulnerability
Published Sep 23, 2014
·Updated
The Zoho Books - Accounting App (aka com.zoho.books) application 3.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Zoho Zoho Books - Accounting App Android=3.1.9
Event History
Sep 23, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6686?
CVE-2014-6686 has a medium severity rating due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2014-6686?
To fix CVE-2014-6686, update the Zoho Books - Accounting App to a later version that verifies X.509 certificates.
3
What type of attack is possible with CVE-2014-6686?
CVE-2014-6686 allows man-in-the-middle attackers to spoof SSL servers and potentially access sensitive information.
4
Which version of the Zoho Books - Accounting App is affected by CVE-2014-6686?
Version 3.1.9 of the Zoho Books - Accounting App is affected by CVE-2014-6686.
5
What platforms are vulnerable due to CVE-2014-6686?
CVE-2014-6686 specifically affects the Android version of the Zoho Books - Accounting App.