Lucene search

K
cvelistCertccCVELIST:CVE-2017-3194
HistoryDec 15, 2017 - 2:00 p.m.

CVE-2017-3194

2017-12-1514:00:00
CWE-295
certcc
www.cve.org

7.8 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.2%

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.

CNA Affected

[
  {
    "product": "Pandora iOS App",
    "vendor": "Pandora Media, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to 8.3.2"
      }
    ]
  }
]

7.8 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.2%

Related for CVELIST:CVE-2017-3194