CVE-2024-27440

MEDIUM

Toyoko Inn <1.13.0-1.3.14 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server certificates, which allows a man-in-the-middle attacker to spoof servers and obtain sensitive information via a crafted certificate.

Scores

CVSS v3 4.8
EPSS 0.0022
EPSS Percentile 12.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (2)
Toyoko Inn IT Solution Co., Ltd./Toyoko Inn official App for Android prior 1.3.14
Toyoko Inn IT Solution Co., Ltd./Toyoko Inn official App for iOS prior to 1.13.0
Published Mar 13, 2024
Tracked Since Feb 18, 2026