Runtastic's vulnerability footprint is concentrated in a narrow portfolio of consumer fitness and health-tracking applications, including its heart-rate monitor, pedometer, and cycling products. The recurring disclosures span this mobile and wearable-focused ecosystem; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Runtastic over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5690MEDIUM The Runtastic Timer (aka com.runtastic.android.timer) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to | Sep 9, 2014 | 5.4 | 18 | NO | NO |
CVE-2014-5689MEDIUM The Runtastic Road Bike (aka com.runtastic.android.roadbike.lite) application 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle | Sep 9, 2014 | 5.4 | 18 | NO | NO |
CVE-2014-5688MEDIUM The Runtastic Pedometer (aka com.runtastic.android.pedometer.lite) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle a | Sep 9, 2014 | 5.4 | 18 | NO | NO |
CVE-2014-5687MEDIUM The Runtastic Mountain Bike (aka com.runtastic.android.mountainbike.lite) application 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the | Sep 9, 2014 | 5.4 | 18 | NO | NO |
CVE-2014-5686MEDIUM The Runtastic Me (aka com.runtastic.android.me.lite) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to | Sep 9, 2014 | 5.4 | 18 | NO | NO |
CVE-2014-5685MEDIUM The Runtastic Heart Rate (aka com.runtastic.android.heartrate.lite) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle | Sep 9, 2014 | 5.4 | 17 | NO | NO |
CVE-2014-5684MEDIUM The Runtastic Running & Fitness (aka com.runtastic.android) application 5.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack | Sep 9, 2014 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Runtastic.
Media articles that mention a CVE ID that affects a product developed by Runtastic — matched by CVE ID, not by vendor name.