CVE-2014-7723
NONE EPSS 18.1%
Published Oct 21, 201411y ago · Modified Jun 17, 20262w ago
Published Oct 21, 2014 11y ago
Last Modified Jun 17, 2026 2w ago
Description
The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Threat Intelligence
EPSS Exploit Probability
18.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-310
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| cmu | carnegie_mellon_silicon_valley | 0.1 | any |
References 3
- kb.cert.org http://www.kb.cert.org/vuls/id/582497
- kb.cert.org http://www.kb.cert.org/vuls/id/727609
- docs.google.com https://docs.google.com/spreadsheets/d/1t5GXwjw82SyunALVJb2w0zi3FoLRIkfGPc7AMjRF0r4/edit?usp=sharing
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.