CVE-2013-3641 describes a critical vulnerability in the Pizza Hut Japan Official Order application for Android, versions prior to 1.1.1.a. The application fails to properly validate X.509 certificates from SSL servers, making it susceptible to man-in-the-middle (MitM) attacks. An attacker could exploit this weakness to spoof legitimate servers and intercept sensitive user information through a crafted certificate. This vulnerability carries a CVSS score of 5.8, indicating a medium severity. Exploitation requires medium attack complexity (AC:M) and can be carried out remotely (AV:N) without authentication (Au:N), potentially leading to partial compromise of confidentiality (C:P) and integrity (I:P). While the FAUCET Risk Score is 28/100, the EPSS score is very low, suggesting a minimal probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE is not listed in CISA's KEV catalog, and there is negligible community discussion or media coverage surrounding this vulnerability, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.0CPE matchmatch criteria | cpe:2.3:a:pizzahut:pizza_hut_japan_official_order_application:*:a:*:*:*:android:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.