High severity8.1NVD Advisory· Published Dec 16, 2017· Updated May 13, 2026
CVE-2017-3194
CVE-2017-3194
Description
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
Affected products
1- Pandora Media, Inc./Pandora iOS Appv5Range: Prior to 8.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/97158nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/collection/XFTAS-Daily-Threat-Assessment-for-March-29-2017-0d704f6eb8163d995bbaf57bbf35a018nvdThird Party AdvisoryVDB Entry
- www.kb.cert.org/vuls/id/342303nvdThird Party AdvisoryUS Government Resource
- www.scmagazine.com/pandora-apple-app-vulnerable-to-mitm-attacks/article/647106/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.