PT-2024-30367 · Planet Fitness · Planet Fitness Workouts

Braelynn Luedtke

+3

·

Published

2024-09-23

·

Updated

2025-02-28

·

CVE-2024-43201

CVSS v4.0

8.7

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/R:U/V:D/RE:L/U:Amber
Name of the Vulnerable Software and Affected Versions The Planet Fitness Workouts iOS and Android mobile apps versions prior to 9.8.12
Description The issue is related to the failure of the Planet Fitness Workouts iOS and Android mobile apps to properly validate TLS certificates. This allows an attacker with appropriate network access to obtain session tokens and sensitive information.
Recommendations For versions prior to 9.8.12, update to version 9.8.12 or later to resolve the issue. As a temporary workaround, consider restricting network access to the app until the update is applied.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2024-43201

Affected Products

Planet Fitness Workouts