VYPR
Unrated severityNVD Advisory· Published Oct 19, 2014· Updated May 6, 2026

CVE-2014-7337

CVE-2014-7337

Description

The Acorn Estate Agents (aka com.acorn.ea) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Acorn Estate Agents app for Android fails to validate SSL certificates, enabling man-in-the-middle attacks to steal sensitive data.

Vulnerability

The Acorn Estate Agents application (com.acorn.ea) version 3.1 for Android does not properly validate X.509 certificates from SSL servers [1]. This means the app accepts any certificate presented by a server, including self-signed or malicious ones, without verifying the chain of trust.

Exploitation

An attacker in a position to intercept network traffic (e.g., on the same Wi-Fi network) can perform a man-in-the-middle attack by presenting a crafted certificate to the app. The app will accept this certificate and establish an HTTPS connection with the attacker's server, allowing the attacker to decrypt and potentially modify the data in transit [1]. No additional authentication or user interaction beyond normal app usage is required.

Impact

A successful attacker can view or modify network traffic that the app sends and receives over HTTPS. This could lead to disclosure of sensitive information such as login credentials, personal data, or financial details. The impact is limited to the data transmitted by the app; the attacker may also inject malicious content into the traffic [1].

Mitigation

The vendor has not released a patched version as of the publication date [1]. Users are advised to avoid using the Acorn Estate Agents app for sensitive transactions until a fix is made available. Alternatively, using a web browser to access the same services may bypass this vulnerability [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.