PT-2017-6464 · Shidax · Restaurant Karaoke Shidax
Yasuyuki Kobayashi
·
Published
2017-07-25
·
Updated
2017-07-31
·
CVE-2015-0904
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Restaurant Karaoke SHIDAX app versions 1.3.3 and earlier
Description
The issue allows remote attackers to obtain sensitive information via a man-in-the-middle attack because the app does not verify SSL certificates.
Recommendations
For versions 1.3.3 and earlier, consider disabling the app's network functionality until a patch is available that properly verifies SSL certificates. Restrict access to sensitive information to minimize the risk of exploitation.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Restaurant Karaoke Shidax