CVE-2017-3194
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
Affected products
Pandora Media, Inc. · Pandora iOS AppReferences
https://exchange.xforce.ibmcloud.com/collection/XFTAS-Daily-Threat-Assessment-for-March-29-2017-0d704f6eb8163d995bbaf57bbf35a018https://www.kb.cert.org/vuls/id/342303https://www.scmagazine.com/pandora-apple-app-vulnerable-to-mitm-attacks/article/647106/http://www.securityfocus.com/bid/97158