First published: Mon Sep 23 2024(Updated: )
The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. Planet Fitness first addressed this vulnerability in version 9.8.12 (released on 2024-07-25) and more recently in version 9.9.13 (released on 2025-02-11).
Credit: 9119a7d8-5eab-497f-8521-727c672e3725
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Planet Fitness Workouts | <9.8.12 | |
Any of | ||
iPhone OS | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43201 is considered a high-severity vulnerability due to its potential for exposing sensitive information.
To fix CVE-2024-43201, users should update the Planet Fitness Workouts app to version 9.8.12 or later released on July 25, 2024.
CVE-2024-43201 allows an attacker with network access to exploit the vulnerability to obtain session tokens and sensitive information.
CVE-2024-43201 affects the Planet Fitness Workouts mobile apps on both iOS and Android platforms prior to version 9.8.12.
CVE-2024-43201 relates to improper validation of TLS certificates, which compromises the security of data transmission.