CVE-2021-20732

The ATOM (ATOM - Smart life App for Android versions prior to 1.8.1 and ATOM - Smart life App for iOS versions prior to 1.8.2) does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on encrypted communication via a crafted certificate.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atomtech:smart_life:*:*:*:*:*:android:*:*
cpe:2.3:a:atomtech:smart_life:*:*:*:*:*:iphone_os:*:*

History

21 Nov 2024, 05:47

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN64064138/index.html - Third Party Advisory () https://jvn.jp/en/jp/JVN64064138/index.html - Third Party Advisory
References () https://www.atomtech.co.jp/news/news/2055/ - Vendor Advisory () https://www.atomtech.co.jp/news/news/2055/ - Vendor Advisory

17 Jun 2021, 18:08

Type Values Removed Values Added
References (MISC) https://www.atomtech.co.jp/news/news/2055/ - (MISC) https://www.atomtech.co.jp/news/news/2055/ - Vendor Advisory
References (MISC) https://jvn.jp/en/jp/JVN64064138/index.html - (MISC) https://jvn.jp/en/jp/JVN64064138/index.html - Third Party Advisory
CPE cpe:2.3:a:atomtech:smart_life:*:*:*:*:*:android:*:*
cpe:2.3:a:atomtech:smart_life:*:*:*:*:*:iphone_os:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.9
CWE CWE-295

09 Jun 2021, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-09 02:15

Updated : 2024-11-21 05:47


NVD link : CVE-2021-20732

Mitre link : CVE-2021-20732

CVE.ORG link : CVE-2021-20732


JSON object : View

Products Affected

atomtech

  • smart_life
CWE
CWE-295

Improper Certificate Validation