CVE-2021-3898

MEDIUM

Motorola Ready For and Device Help < 2021-04-08 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://support.lenovo.com/us/en/product_security/LEN-58311

Scores

CVSS v3 6.8
EPSS 0.0043
EPSS Percentile 34.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (2)
motorola/device_help < 2021-04-08
motorola/ready_for < 2021-04-08
Published Apr 22, 2022
Tracked Since Feb 18, 2026