CVE-2014-6803: Medium severity bank of moscow eirts rent vulnerability
The Bank of Moscow EIRTS Rent (aka ru.bm.rbs.android) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6803?
CVE-2014-6803 has a high severity risk due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-6803?
To fix CVE-2014-6803, ensure that the application is updated to a newer version that correctly verifies X.509 certificates.
What systems are affected by CVE-2014-6803?
CVE-2014-6803 affects the Bank of Moscow EIRTS Rent application version 1.0.0 on Android devices.
What type of attack does CVE-2014-6803 allow?
CVE-2014-6803 allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
What happens if I don't address CVE-2014-6803?
Failing to address CVE-2014-6803 can lead to sensitive information being exposed to unauthorized parties.