PT-2017-8543 · Google+1 · Coordinate Plus App For Android+1

Gaku Taniguchi

·

Published

2017-04-21

·

Updated

2021-09-09

·

CVE-2016-4840

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Coordinate Plus App for Android versions 1.0.2 and earlier Coordinate Plus App for iOS versions 1.0.2 and earlier
Description The issue concerns the failure to verify SSL certificates. This could potentially allow for man-in-the-middle attacks.
Recommendations For Coordinate Plus App for Android versions 1.0.2 and earlier, update to a version that properly verifies SSL certificates. For Coordinate Plus App for iOS versions 1.0.2 and earlier, update to a version that properly verifies SSL certificates.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4840

Affected Products

Coordinate Plus App For Android
Coordinate Plus App For Ios