First published: Fri Sep 29 2017(Updated: )
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Site24x7 Mobile Network Poller | <=1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14582 is considered a high severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2017-14582, you should update the Zoho Site24x7 Mobile Network Poller application to version 1.1.5 or later.
The implications of CVE-2017-14582 include the risk of sensitive information being compromised through the use of self-signed certificates.
Versions of Zoho Site24x7 Mobile Network Poller prior to 1.1.5 are affected by CVE-2017-14582.
Yes, CVE-2017-14582 can potentially lead to data breaches as attackers can intercept sensitive information.