PT-2017-6464 · Shidax · Restaurant Karaoke Shidax

Yasuyuki Kobayashi

·

Publicado

2017-07-25

·

Atualizado

2017-07-31

·

CVE-2015-0904

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Restaurant Karaoke SHIDAX app versions 1.3.3 and earlier
Description The issue allows remote attackers to obtain sensitive information via a man-in-the-middle attack because the app does not verify SSL certificates.
Recommendations For versions 1.3.3 and earlier, consider disabling the app's network functionality until a patch is available that properly verifies SSL certificates. Restrict access to sensitive information to minimize the risk of exploitation.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-0904

Produtos afetados

Restaurant Karaoke Shidax