Description
Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Betrend Corporation and ICHIRAN INC. / Ichiran App for iOS and Ichiran App for AndroidIchiran App for iOS versions prior to 3.1.0, and Ichiran App for Android versions prior to 3.1.0 – Ichiran App for iOS versions prior to 3.1.0, and Ichiran App for Android versions prior to 3.1.0