CVE-2018-0591

MEDIUM

KINEPASS < 3.1.1 (Android) and < 3.1.2 (iOS) - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry third-party-advisory x_refsource_jvn
https://jvn.jp/en/jp/JVN83671755/

Scores

CVSS v3 5.9
EPSS 0.0087
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-295
Status published
Products (2)
t-joy/kinepass < 3.1.1
t-joy/kinepass < 3.1.2
Published May 14, 2018
Tracked Since Feb 18, 2026