First published: Sun Oct 19 2014(Updated: )
The Autocar India (aka com.magzter.autocarindia) application 3.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Magzter Autocar India | =3.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7071 has a medium severity rating due to its potential for exploitation by man-in-the-middle attacks.
CVE-2014-7071 allows attackers to spoof SSL servers without certificate verification, exposing sensitive user information.
To fix CVE-2014-7071, update the Autocar India application to a version that properly verifies SSL certificates.
CVE-2014-7071 specifically affects version 3.03 of the Autocar India application on Android devices.
Users of the Autocar India application version 3.03 on Android are vulnerable to CVE-2014-7071.