CVE-2017-3212
MEDIUMSccu Space Coast Credit Union - Improper Certificate Validation
Title source: ruleDescription
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References (3)
Scores
CVSS v3
5.9
EPSS
0.0022
EPSS Percentile
44.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-295
Status
published
Affected Products (3)
sccu/space_coast_credit_union
< 2.1.0.1104
sccu/space_coast_credit_union
< 2.2
n/a/Space Coast Credit Union Mobile
< Space Coast Credit Union Mobile
Timeline
Published
May 05, 2017
Tracked Since
Feb 18, 2026