CVE-2014-7798
Description
The Coca-Cola FM Brasil (aka com.enyetech.radio.coca_cola.fm_br) application 2.0.41709 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Coca-Cola FM Brasil Android app fails to validate SSL certificates, enabling man-in-the-middle attacks to intercept sensitive data.
Vulnerability
The Coca-Cola FM Brasil (com.enyetech.radio.coca_cola.fm_br) application version 2.0.41709 for Android does not properly verify X.509 certificates from SSL servers [1]. This means the app accepts any certificate presented during an HTTPS connection, including self-signed or forged certificates. The vulnerability was identified through dynamic SSL testing as part of a broader study of Android applications [2].
Exploitation
An attacker positioned on the same network as the victim (e.g., public Wi-Fi) can perform a man-in-the-middle attack. By presenting a crafted certificate to the app, the attacker can intercept all HTTPS traffic between the app and its servers. No authentication or user interaction beyond the victim using the app is required.
Impact
Successful exploitation allows the attacker to view or modify network traffic that should have been encrypted. This could lead to disclosure of sensitive information such as login credentials, personal data, or other content transmitted by the app. The impact is limited to the data exchanged by this specific application.
Mitigation
The vendor has not released a patched version as of the publication date (2014-10-21). Users are advised to avoid using this application and instead access Coca-Cola FM Brasil content through a web browser, which typically provides proper SSL validation [1]. The app may be removed from the device to eliminate the risk.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:enyetech:coca-cola_fm_brasil:2.0.41709:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:a:enyetech:coca-cola_fm_brasil:2.0.41709:*:*:*:*:android:*:*
- (no CPE)range: = 2.0.41709
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.kb.cert.org/vuls/id/317353nvdUS Government Resource
- www.kb.cert.org/vuls/id/582497nvdUS Government Resource
- docs.google.com/spreadsheets/d/1t5GXwjw82SyunALVJb2w0zi3FoLRIkfGPc7AMjRF0r4/editnvd
News mentions
0No linked articles in our index yet.