First published: Mon Jun 22 2020(Updated: )
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Sophos Secure Email | <=3.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14980 is a vulnerability in the Sophos Secure Email application for Android that allows an attacker to perform a Man-in-the-Middle attack due to missing SSL certificate validation.
The severity of CVE-2020-14980 is medium with a CVSS score of 5.9.
CVE-2020-14980 affects Sophos Secure Email application through version 3.9.4 for Android by enabling a Man-in-the-Middle attack due to missing SSL certificate validation.
To fix CVE-2020-14980, make sure to update the Sophos Secure Email application on your Android device to version 3.9.5 or higher.
You can find more information about CVE-2020-14980 on the following websites: - [Packet Storm Security](http://packetstormsecurity.com/files/158322/Sophos-Secure-Email-Android-Application-3.9.4-Man-In-The-Middle.html) - [Info-Sec Advisory](https://www.info-sec.ca/advisories/Sophos-Secure-Email.html)