CVE-2021-20732

The ATOM (ATOM - Smart life App for Android versions prior to 1.8.1 and ATOM - Smart life App for iOS versions prior to 1.8.2) does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on encrypted communication via a crafted certificate.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atomtech:smart_life:*:*:*:*:*:android:*:*
cpe:2.3:a:atomtech:smart_life:*:*:*:*:*:iphone_os:*:*

History

No history.

Information

Published : 2021-06-09 02:15

Updated : 2024-02-28 18:28


NVD link : CVE-2021-20732

Mitre link : CVE-2021-20732

CVE.ORG link : CVE-2021-20732


JSON object : View

Products Affected

atomtech

  • smart_life
CWE
CWE-295

Improper Certificate Validation