CVE-2014-7475: Medium severity ionic vulnerability
The Ionic View (aka com.ionic.viewapp) application 0.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7475?
CVE-2014-7475 is considered a high severity vulnerability due to its potential exposure to man-in-the-middle attacks.
How do I fix CVE-2014-7475?
To fix CVE-2014-7475, upgrade the Ionic View application to a version that properly verifies X.509 certificates.
What is the impact of CVE-2014-7475?
The impact of CVE-2014-7475 is that attackers can spoof SSL servers and intercept sensitive information from users.
Which version of the application is affected by CVE-2014-7475?
CVE-2014-7475 affects version 0.0.2 of the Ionic View application on Android.
Can CVE-2014-7475 affect data privacy?
Yes, CVE-2014-7475 can significantly compromise data privacy by allowing attackers to access sensitive information through unverified SSL connections.