CVE-2014-7242
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obtain sensitive information by…
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obtain sensitive information by leveraging failure to verify SSL/TLS server certificates.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- ms-ins/sumaho · ms-ins/sumaho driving capability diagnosis
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN27388160/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000125.htmlThird Party Advisory, VDB Entry
- http://jvn.jp/en/jp/JVN27388160/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000125.htmlThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.