The ATOM (ATOM - Smart life App for Android versions prior to 1.8.1 and ATOM - Smart life App for iOS versions prior to 1.8.2) does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on encrypted communication via a crafted certificate.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.atomtech.co.jp/news/news/2055/ | vendor advisory |
https://jvn.jp/en/jp/JVN64064138/index.html | third party advisory |