VYPR
Unrated severityNVD Advisory· Published Sep 9, 2014· Updated May 6, 2026

CVE-2014-5535

CVE-2014-5535

Description

The Baby Get Up - Kids Care (aka air.brown.jordansa.getup) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Baby Get Up - Kids Care Android app fails to validate SSL certificates, enabling man-in-the-middle attacks to intercept sensitive data.

Vulnerability

The Baby Get Up - Kids Care application (package air.brown.jordansa.getup) version 1.0.3 for Android fails to properly validate X.509 certificates presented by HTTPS servers. This means the app does not verify that the certificate chain is signed by a trusted root certificate authority, as required for secure SSL/TLS connections [1].

Exploitation

An attacker positioned on the same network as the victim (e.g., via a rogue Wi‑Fi hotspot or ARP spoofing) can perform a man‑in‑the‑middle attack. By presenting a crafted certificate that the app does not reject, the attacker can intercept all HTTPS traffic between the app and its backend servers [1].

Impact

Successful exploitation allows the attacker to view or modify network traffic that should have been protected by HTTPS. This can lead to disclosure of sensitive information such as user credentials or personal data, and potentially arbitrary code execution depending on the app's functionality [1].

Mitigation

The vendor has not released a patched version as of the publication date. Users are advised to avoid using this application and instead access the service via a web browser, which typically implements proper certificate validation [1]. The application may be considered obsolete; no fix is known.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.