CVE-2018-0691
MEDIUMKDDI, NTT DOCOMO, and Softbank +Message Apps - Improper Certificate Validation
Title source: llmDescription
Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References (4)
Core 4
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.au.com/information/notice_mobile/service/2018-002/
Patch, Vendor Advisory x_refsource_misc
https://www.softbank.jp/mobile/info/personal/news/service/20180927a/
Third Party Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN37288228/index.html
Patch, Vendor Advisory x_refsource_misc
https://www.nttdocomo.co.jp/info/notice/page/180927_00.html
Scores
CVSS v3
5.9
EPSS
0.0067
EPSS Percentile
47.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-295
Status
published
Products (4)
kddi/\+_message
< 1.0.6
ntt_tocomo/\+_message
< 1.1.23
ntttocomo/\+_message
< 42.40.2800
softbank/\+_message
< 10.1.7
Published
Nov 15, 2018
Tracked Since
Feb 18, 2026