First published: Fri Jan 31 2020(Updated: )
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Fujixerox Apeosware Management Suite 2 | >=2.0.0<=2.0.5 | |
Fujixerox Apeosware Management Suite 2 | >=2.0.0<=2.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5526.
The severity of CVE-2020-5526 is medium (5.9).
The AWMS Mobile App for Android versions 2.0.0 to 2.0.5 and iOS versions 2.0.0 to 2.0.8 are affected by CVE-2020-5526.
CVE-2020-5526 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
For a fix or patch for CVE-2020-5526, please refer to the vendor's official website.