CVE-2017-2278

The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version 2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References
Link Resource
http://www.iid.co.jp/information/170714.html Broken Link Third Party Advisory
https://jvn.jp/en/jp/JVN24238648/index.html Third Party Advisory VDB Entry
http://www.iid.co.jp/information/170714.html Broken Link Third Party Advisory
https://jvn.jp/en/jp/JVN24238648/index.html Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:iid:rbb_speed_test:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:iid:rbb_speed_test:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:23

Type Values Removed Values Added
References () http://www.iid.co.jp/information/170714.html - Broken Link, Third Party Advisory () http://www.iid.co.jp/information/170714.html - Broken Link, Third Party Advisory
References () https://jvn.jp/en/jp/JVN24238648/index.html - Third Party Advisory, VDB Entry () https://jvn.jp/en/jp/JVN24238648/index.html - Third Party Advisory, VDB Entry

Information

Published : 2017-08-02 16:29

Updated : 2024-11-21 03:23


NVD link : CVE-2017-2278

Mitre link : CVE-2017-2278

CVE.ORG link : CVE-2017-2278


JSON object : View

Products Affected

apple

  • iphone_os

iid

  • rbb_speed_test

google

  • android
CWE
CWE-295

Improper Certificate Validation