Vulnerability Note VU#690343
Acer Portal app for Android does not properly validate SSL certificates
Overview
The Acer Portal app for Android allows customers to connect to the Acer Cloud. The Acer Portal app, from version 3.9.3.2003 to 3.9.3.2006, does not properly validate SSL certificates when connecting to the Acer Cloud.
Description
CVE-2016-5648 - CWE-295: Improper Certificate Validation The Acer Portal app for Android, from version 3.9.3.2003 to 3.9.3.2006, does not properly validate SSL certificates when connecting to the Acer Cloud. A remote unauthenticated attacker capable of conducting a man-in-the-middle attack may be able to impersonate the Acer Cloud and obtain a victim's account credentials or other cloud information. |
Impact
A remote unauthenticated attacker capable of conducting a man-in-the-middle attack may be able to impersonate the Acer Cloud and obtain a victim's account credentials or other cloud information. |
Solution
Apply an update |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Acer | Affected | 02 Jun 2016 | 05 Jul 2016 |
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 5.8 | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Temporal | 4.5 | E:POC/RL:OF/RC:C |
Environmental | 3.4 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Credit
Thanks to David Coomber for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
- CVE IDs: CVE-2016-5648
- Date Public: 05 Jul 2016
- Date First Published: 05 Jul 2016
- Date Last Updated: 05 Jul 2016
- Document Revision: 8
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.