CVE-2017-8943: Medium severity Puma Pumatrac Iphone Os vulnerability
Published May 15, 2017
·Updated
The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Puma Pumatrac Iphone Os=3.0.2
Event History
May 15, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8943?
CVE-2017-8943 has a medium severity level due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2017-8943?
To fix CVE-2017-8943, update the PUMATRAC app to a version that properly verifies X.509 certificates.
3
What types of attacks can exploit CVE-2017-8943?
CVE-2017-8943 can be exploited through man-in-the-middle attacks, allowing attackers to intercept sensitive data.
4
Which versions of the PUMATRAC app are affected by CVE-2017-8943?
CVE-2017-8943 specifically affects version 3.0.2 of the PUMATRAC app on iOS devices.
5
What information can be compromised due to CVE-2017-8943?
CVE-2017-8943 can lead to the compromise of sensitive information transmitted over SSL due to the lack of proper certificate verification.