CVE-2014-6708 describes a critical vulnerability in the Sporting Club Uphoria Android application (version 2.1.0), specifically affecting the sportinginnovations utah_jazz product. The application fails to properly validate X.509 certificates from SSL servers, enabling man-in-the-middle (MITM) attackers to spoof legitimate servers. This flaw could lead to the interception and compromise of sensitive user information. The vulnerability carries a CVSS score of 5.4, indicating a medium severity. An attacker could exploit this remotely (AV:A) with moderate complexity (AC:M), potentially leading to partial compromise of confidentiality, integrity, and availability (C:P/I:P/A:P). The underlying weakness is categorized as CWE-310, "Cryptographic Issues." Currently, there is no evidence of active exploitation, and it is not listed in the CISA KEV catalog. No public exploit code, such as Metasploit or ExploitDB modules, is available, and there is no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:sportinginnovations:utah_jazz:2.0.0:*:*:*:*:android:*:* |
CVSS version used by this source: 2.0
AV:A/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.