CVE-2017-8059

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
05/05/2017
Last modified:
13/05/2026

Description

Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:foxitsoftware:foxit_pdf:5.2.1:*:*:*:*:iphone_os:*:*
cpe:2.3:a:foxitsoftware:foxit_pdf:5.3.2:*:*:*:*:iphone_os:*:*