CVE-2018-0691

MEDIUM

KDDI, NTT DOCOMO, and Softbank +Message Apps - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

References (4)

Core 4
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.au.com/information/notice_mobile/service/2018-002/
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN37288228/index.html
Patch, Vendor Advisory x_refsource_misc
https://www.nttdocomo.co.jp/info/notice/page/180927_00.html

Scores

CVSS v3 5.9
EPSS 0.0067
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-295
Status published
Products (4)
kddi/\+_message < 1.0.6
ntt_tocomo/\+_message < 1.1.23
ntttocomo/\+_message < 42.40.2800
softbank/\+_message < 10.1.7
Published Nov 15, 2018
Tracked Since Feb 18, 2026