CVE-2019-16252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
12/06/2020
Last modified:
22/06/2020

Description

Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nutfind:nutfind:*:*:*:*:*:android:*:* 3.9.12 (including)


References to Advisories, Solutions, and Tools