CVE-2016-4840: Medium severity toshiba coordinate plus vulnerability
Published Apr 21, 2017
·Updated
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
Affected Software
2 affected components
Toshiba Coordinate Plus Android<=1.0.2
Toshiba Coordinate Plus Iphone Os<=1.0.2
Event History
Apr 21, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4840?
CVE-2016-4840 has a medium severity level due to its potential to allow man-in-the-middle attacks.
2
How do I fix CVE-2016-4840?
To fix CVE-2016-4840, update the Coordinate Plus App to version 1.0.3 or later which includes SSL certificate verification.
3
What systems are affected by CVE-2016-4840?
CVE-2016-4840 affects Coordinate Plus App for Android version 1.0.2 and earlier and iOS version 1.0.2 and earlier.
4
What are the potential risks of CVE-2016-4840?
The potential risks of CVE-2016-4840 include data interception and impersonation in insecure network environments.
5
Is CVE-2016-4840 still a concern for users?
CVE-2016-4840 is still a concern for users who have not updated their app to the latest version that addresses the vulnerability.