Skip to content
appaloosa scout logo main rounded
HIGH 7.5

CVE-2017-3190

Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.

CVSS v3 CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
axs flash_seats iOS ≤1.9.51 cpe:2.3:a:axs:flash_seats:*:*:*:*:*:iphone_os:*:*
axs flash_seats Android ≤1.7.9 cpe:2.3:a:axs:flash_seats:*:*:*:*:*:android:*:*
View on NVD ↗