First published: Fri Apr 21 2017(Updated: )
Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Kunai Browser For Remote Service | =2.1.2 | |
Cybozu Kunai Browser For Remote Service | =2.1.3 | |
Cybozu Kunai Browser For Remote Service | =3.0.0 | |
Cybozu Kunai Browser For Remote Service | =3.0.1 | |
Cybozu Kunai Browser For Remote Service | =3.0.2 | |
Cybozu Kunai Browser For Remote Service | =3.0.3 | |
Cybozu Kunai Browser For Remote Service | =3.0.4 | |
Cybozu Kunai Browser For Remote Service | =2.0.3 | |
Cybozu Kunai Browser For Remote Service | =2.0.3.1 | |
Cybozu Kunai Browser For Remote Service | =2.0.4 | |
Cybozu Kunai Browser For Remote Service | =2.0.5 | |
Cybozu Kunai Browser For Remote Service | =2.1.0 | |
Cybozu Kunai Browser For Remote Service | =2.1.1 | |
Cybozu Kunai Browser For Remote Service | =3.0._5 | |
Cybozu Kunai Browser For Remote Service | =3.0.0 | |
Cybozu Kunai Browser For Remote Service | =3.0.1 | |
Cybozu Kunai Browser For Remote Service | =3.0.2 | |
Cybozu Kunai Browser For Remote Service | =3.0.3 | |
Cybozu Kunai Browser For Remote Service | =3.0.4 | |
Cybozu Kunai Browser For Remote Service | =3.0.6 | |
Cybozu Kunai Browser For Remote Service | =3.0.7 | |
Cybozu Kunai Browser For Remote Service | =3.1.0 | |
Cybozu Kunai Browser For Remote Service | =3.1.1 | |
Cybozu Kunai Browser For Remote Service | =3.1.2 | |
Cybozu Kunai Browser For Remote Service | =3.1.3 | |
Cybozu Kunai Browser For Remote Service | =3.1.4 | |
Cybozu Kunai Browser For Remote Service | =3.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1187 allows attackers to intercept and manipulate data due to the lack of SSL certificate verification.
To mitigate CVE-2016-1187, ensure you update to the latest version of Cybozu Kunai that includes SSL certificate verification.
CVE-2016-1187 affects Cybozu Kunai for iPhone versions 2.0.3 to 3.1.5 and Android versions 2.1.2 to 3.0.4.
Yes, CVE-2016-1187 is considered serious as it compromises the security of communications in the affected applications.
If you cannot update due to compatibility issues, consider using alternate secure applications or implementing additional security measures to protect your data.