Vulnerability Description
The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ntv | News 24 | < 3.0.0 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN01236065/index.htmlThird Party Advisory
- https://play.google.com/store/apps/details?id=jp.co.ntv.news24&hl=enProductThird Party Advisory
- http://jvn.jp/en/jp/JVN01236065/index.htmlThird Party Advisory
- https://play.google.com/store/apps/details?id=jp.co.ntv.news24&hl=enProductThird Party Advisory
FAQ
What is CVE-2019-6032?
CVE-2019-6032 is a vulnerability with a CVSS score of 7.4 (HIGH). The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certific...
How severe is CVE-2019-6032?
CVE-2019-6032 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6032?
Check the references section above for vendor advisories and patch information. Affected products include: Ntv News 24.