CVE-2014-6692: Medium severity wps office vulnerability
The Kingsoft Clip (Office Tool) (aka cn.wps.clip) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6692?
CVE-2014-6692 has a severity rating that indicates a vulnerability allowing man-in-the-middle attacks.
How do I fix CVE-2014-6692?
To fix CVE-2014-6692, upgrade to a version of the Kingsoft Clip application that properly verifies SSL certificates.
What are the potential impacts of CVE-2014-6692?
The potential impacts of CVE-2014-6692 include data interception and unauthorized access to sensitive information.
Who is affected by CVE-2014-6692?
Users of Kingsoft Clip version 1.5.1 for Android are affected by CVE-2014-6692.
What type of attack is possible due to CVE-2014-6692?
CVE-2014-6692 can be exploited through man-in-the-middle attacks due to improper SSL certificate verification.