CVE-2017-3194 Information
Feb 14, 2021
cve
Description
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/97158 https://exchange.xforce.ibmcloud.com/collection/XFTAS-Daily-Threat-Assessment-for-March-29-2017-0d704f6eb8163d995bbaf57bbf35a018 https://www.kb.cert.org/vuls/id/342303 https://www.scmagazine.com/pandora-apple-app-vulnerable-to-mitm-attacks/article/647106/
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: