CVE-2016-5648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
08/06/2017
Last modified:
20/04/2025

Description

Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:acer:acer_portal:*:*:*:*:*:android:*:* 3.9.3.2006 (including)