CVE-2014-7560: Medium severity fabasoft cloud vulnerability
The Fabasoft Cloud (aka com.fabasoft.android.cmis.foliocloud) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7560?
CVE-2014-7560 has a severity rating of medium with a score of 5.4.
How does CVE-2014-7560 affect the Fabasoft Cloud application?
CVE-2014-7560 allows man-in-the-middle attackers to spoof servers by not verifying X.509 certificates.
What can attackers obtain through CVE-2014-7560?
Attackers can potentially obtain sensitive information by exploiting CVE-2014-7560 with a crafted certificate.
What versions of the Fabasoft Cloud app are vulnerable to CVE-2014-7560?
The vulnerability CVE-2014-7560 affects version 3.0.1 of the Fabasoft Cloud app for Android.
How can I mitigate the risk of CVE-2014-7560 if I use the Fabasoft Cloud app?
To mitigate CVE-2014-7560, ensure you are using a version of the Fabasoft Cloud app that has resolved the certificate verification issue.