CVE-2017-3212
Last modified
CVE-2017-3212 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sccu | Space Coast Credit Union | <= 2.1.0.1104 |
| Sccu | Space Coast Credit Union | <= 2.2 |
References
- http://www.kb.cert.org/vuls/id/556600Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/98307Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/556600Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/98307Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3212?
How severe is CVE-2017-3212?
How do I fix CVE-2017-3212?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-3206The Java implementation of AMF3 deserializers used by Flamin…
- CVE-2017-3207The Java implementations of AMF3 deserializers in WebORB for…
- CVE-2017-3208The Java implementation of AMF3 deserializers used by WebORB…
- CVE-2017-3209The DBPOWER U818A WIFI quadcopter drone provides FTP access …8.1
- CVE-2017-3210Applications developed using the Portrait Display SDK, versi…
- CVE-2017-3211Yopify, an e-commerce notification plugin, up to April 06, 2…5.3
- CVE-2017-3213The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does …
- CVE-2017-3214The Milwaukee ONE-KEY Android mobile application stores the …7.5
- CVE-2017-3215The Milwaukee ONE-KEY Android mobile application uses bearer…
- CVE-2017-3216WiMAX routers based on the MediaTek SDK (libmtk) that use a …
- CVE-2017-3217CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SM…
- CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for …
Are you affected by CVE-2017-3212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
