CVE-2023-33757
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
25/01/2024
Last modified:
20/06/2025
Description
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:splicecom:ipcs:*:*:*:*:*:android:*:* | 1.8.5 (including) | |
| cpe:2.3:a:splicecom:ipcs:1.3.4:*:*:*:*:iphone_os:*:* | ||
| cpe:2.3:a:splicecom:ipcs2:*:*:*:*:*:iphone_os:*:* | 2.8 (including) |
To consult the complete list of CPE names with products and versions, see this page



