imPC@ndo IT

Tracker / CVE-2014-1910

CVE-2014-1910

Medium 5.8

Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected products and versions

citrix sharefile_mobile · … → 2.4
citrix sharefile_mobile_for_tablets · … → 2.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References