8.8
CWE
295
Advisory Published
Updated

CVE-2024-43201: Planet Fitness Workouts mobile apps do not properly validate TLS certificates

First published: Mon Sep 23 2024(Updated: )

The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. Planet Fitness first addressed this vulnerability in version 9.8.12 (released on 2024-07-25) and more recently in version 9.9.13 (released on 2025-02-11).

Credit: 9119a7d8-5eab-497f-8521-727c672e3725

Affected SoftwareAffected VersionHow to fix
All of
Planet Fitness Workouts<9.8.12
Any of
iPhone OS
Android

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-43201?

    CVE-2024-43201 is considered a high-severity vulnerability due to its potential for exposing sensitive information.

  • How do I fix CVE-2024-43201?

    To fix CVE-2024-43201, users should update the Planet Fitness Workouts app to version 9.8.12 or later released on July 25, 2024.

  • What kind of attack is possible with CVE-2024-43201?

    CVE-2024-43201 allows an attacker with network access to exploit the vulnerability to obtain session tokens and sensitive information.

  • Which platforms are affected by CVE-2024-43201?

    CVE-2024-43201 affects the Planet Fitness Workouts mobile apps on both iOS and Android platforms prior to version 9.8.12.

  • What does CVE-2024-43201 relate to in terms of security?

    CVE-2024-43201 relates to improper validation of TLS certificates, which compromises the security of data transmission.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203