First published: Fri Oct 03 2014(Updated: )
The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
H2o Human Harmony Organization | =1.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6905 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2014-6905, it is recommended to update the H2O Human Harmony Organization application to a version that properly validates X.509 certificates.
CVE-2014-6905 affects the H2O Human Harmony Organization application version 1.6.5 on Android devices.
CVE-2014-6905 allows man-in-the-middle attackers to spoof SSL servers and capture sensitive information.
It is not safe to use version 1.6.5 of the H2O Human Harmony Organization app due to the vulnerability CVE-2014-6905.