Vulnerability Description
Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier, and Jiyu Kukan Toku-Toku coupon App for Android versions 3.5.0 and earlier are vulnerable to improper server certificate verification. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker to eavesdrop on an encrypted communication.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Runsystem | Jiyu Kukan Toku-Toku Coupon | <= 3.5.0 |
Related Weaknesses (CWE)
References
- https://apps.apple.com/jp/app/%E8%87%AA%E9%81%8A%E7%A9%BA%E9%96%93%E3%81%A8%E3%8Product
- https://jvn.jp/en/jp/JVN33836375/Third Party Advisory
- https://play.google.com/store/apps/details?id=jp.runsystemProduct
- https://www.runsystem.co.jp/g1-pr/17570Vendor Advisory
- https://apps.apple.com/jp/app/%E8%87%AA%E9%81%8A%E7%A9%BA%E9%96%93%E3%81%A8%E3%8Product
- https://jvn.jp/en/jp/JVN33836375/Third Party Advisory
- https://play.google.com/store/apps/details?id=jp.runsystemProduct
- https://www.runsystem.co.jp/g1-pr/17570Vendor Advisory
FAQ
What is CVE-2023-29501?
CVE-2023-29501 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier, and Jiyu Kukan Toku-Toku coupon App for Android versions 3.5.0 and earlier are vulnerable to improper server certificate verificatio...
How severe is CVE-2023-29501?
CVE-2023-29501 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29501?
Check the references section above for vendor advisories and patch information. Affected products include: Runsystem Jiyu Kukan Toku-Toku Coupon.