VulnerabilityModified
CVE-2012-4918
Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive information via a Man-in-the-Middle (MITM) attack.
MEDIUM 5.8EPSS 1.07%
Does this matter?
Lower severity and a low EPSS score (1.07%). Track it; it rarely justifies an emergency change on its own.
Description
Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive information via a Man-in-the-Middle (MITM) attack.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- activision/call of duty elite
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://osvdb.org/89070
- http://secunia.com/advisories/51366Vendor Advisory
- http://www.securityfocus.com/bid/57225
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81116
- http://osvdb.org/89070
- http://secunia.com/advisories/51366Vendor Advisory
- http://www.securityfocus.com/bid/57225
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81116
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.