CVE-2017-8943 describes a vulnerability in the PUMA PUMATRAC app 3.0.2 for iOS, where the application fails to validate X.509 certificates from SSL servers. This flaw allows man-in-the-middle attackers to spoof legitimate servers and intercept sensitive user information through the use of crafted certificates. The vulnerability has a CVSS score of 5.9 (MEDIUM), indicating a moderate severity. Its attack vector is network-based with high attack complexity, requiring no user interaction, and could lead to high confidentiality impact by allowing attackers to obtain sensitive data. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.2CPE matchmatch criteria | cpe:2.3:a:puma:pumatrac:3.0.2:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.