CVE-2020-5526: Medium severity Fujixerox Apeosware Management Suite Android vulnerability
Published Jan 31, 2020
·Updated
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
2 affected components
Fujixerox Apeosware Management Suite Android>=2.0.0<=2.0.5
Fujixerox Apeosware Management Suite Iphone Os>=2.0.0<=2.0.8
Event History
Jan 31, 2020
CVE Published
via MITRE·03:35 AM
Data Sourced
via MITRE·03:35 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5526.
2
What is the severity of CVE-2020-5526?
The severity of CVE-2020-5526 is medium (5.9).
3
Which software versions are affected by CVE-2020-5526?
The AWMS Mobile App for Android versions 2.0.0 to 2.0.5 and iOS versions 2.0.0 to 2.0.8 are affected by CVE-2020-5526.
4
What is the impact of CVE-2020-5526?
CVE-2020-5526 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
5
Is there a fix available for CVE-2020-5526?
For a fix or patch for CVE-2020-5526, please refer to the vendor's official website.