CVE-2014-6905: Medium severity h2o human harmony organization vulnerability
The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6905?
CVE-2014-6905 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-6905?
To fix CVE-2014-6905, it is recommended to update the H2O Human Harmony Organization application to a version that properly validates X.509 certificates.
What systems are affected by CVE-2014-6905?
CVE-2014-6905 affects the H2O Human Harmony Organization application version 1.6.5 on Android devices.
What kind of attack can be executed using CVE-2014-6905?
CVE-2014-6905 allows man-in-the-middle attackers to spoof SSL servers and capture sensitive information.
Can I still use version 1.6.5 of the H2O Human Harmony Organization app safely?
It is not safe to use version 1.6.5 of the H2O Human Harmony Organization app due to the vulnerability CVE-2014-6905.