Описание
The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help.
Ссылки
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:uidai:maadhaar:1.2.7:*:*:*:*:android:*:*
EPSS
Процентиль: 36%
0.00154
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 7.4
github
больше 3 лет назад
The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help.
EPSS
Процентиль: 36%
0.00154
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-295