Vulnerability Details CVE-2017-8059
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.9%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 4.3
Products affected by CVE-2017-8059
-
cpe:2.3:a:foxitsoftware:foxit_pdf:5.2.1
-
cpe:2.3:a:foxitsoftware:foxit_pdf:5.3.2