VulnerabilityModified
CVE-2014-1910
Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
MEDIUM 5.8EPSS 0.86%
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 0.86% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- citrix/sharefile mobile · citrix/sharefile mobile for tablets
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/57020Vendor Advisory
- http://support.citrix.com/article/CTX140303Patch, Vendor Advisory
- http://www.securitytracker.com/id/1029791
- http://secunia.com/advisories/57020Vendor Advisory
- http://support.citrix.com/article/CTX140303Patch, Vendor Advisory
- http://www.securitytracker.com/id/1029791
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.