First published: Tue Sep 23 2014(Updated: )
The Kingsoft Clip (Office Tool) (aka cn.wps.clip) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
WPS Office | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6692 has a severity rating that indicates a vulnerability allowing man-in-the-middle attacks.
To fix CVE-2014-6692, upgrade to a version of the Kingsoft Clip application that properly verifies SSL certificates.
The potential impacts of CVE-2014-6692 include data interception and unauthorized access to sensitive information.
Users of Kingsoft Clip version 1.5.1 for Android are affected by CVE-2014-6692.
CVE-2014-6692 can be exploited through man-in-the-middle attacks due to improper SSL certificate verification.