CVE-2014-7626: Medium severity arkeia network backup vulnerability
Published Oct 20, 2014
·Updated
The Atme (aka com.bedigital.atme) application 1.0.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Atme Atme Android=1.0.10
Event History
Oct 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7626?
CVE-2014-7626 has been classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2014-7626?
To fix CVE-2014-7626, upgrade the Atme application to a version that verifies X.509 certificates properly.
3
What kind of vulnerability is CVE-2014-7626?
CVE-2014-7626 is a security vulnerability related to improper SSL certificate validation.
4
Which software versions are affected by CVE-2014-7626?
CVE-2014-7626 specifically affects Atme application version 1.0.10 for Android.
5
What impact does CVE-2014-7626 have on users?
CVE-2014-7626 allows attackers to impersonate legitimate servers, potentially leading to the exposure of sensitive data.