Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.
2017-06-08T20:29:00.250
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | acer | acer_portal | ≤ 3.9.3.2006 | Yes |