First published: Tue Oct 21 2014(Updated: )
The Condor S.E. (aka com.app_condorsoutheast.layout) application 1.399 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HTCondor | =1.399 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7754 is classified as a critical vulnerability due to its potential for man-in-the-middle attacks.
CVE-2014-7754 allows exploitation by failing to verify X.509 certificates, making it possible for attackers to spoof SSL servers.
CVE-2014-7754 affects Android devices running the Condor S.E. application version 1.399.
To mitigate CVE-2014-7754, update the Condor S.E. application to a version that properly validates SSL certificates.
Sensitive information such as user credentials could be compromised due to CVE-2014-7754.