CVE Vulnerabilities

CVE-2023-33757

Improper Certificate Validation

Published: Jan 25, 2024 | Modified: Jan 31, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Ipcs Splicecom * 1.8.5 (including)
Ipcs Splicecom 1.3.4 (including) 1.3.4 (including)
Ipcs2 Splicecom * 2.8 (including)

Potential Mitigations

References