PT-2023-32172 · Line · Line Client For Ios

CVE-2023-5554

·

Published

2023-10-12

·

Updated

2023-10-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LINE Client for iOS versions prior to 13.16.0
Description The issue is related to a lack of TLS certificate verification in log transmission of a financial module. This could potentially lead to security risks, but specific details about the estimated number of affected devices or real-world incidents are not provided.
Recommendations For versions prior to 13.16.0, update to version 13.16.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the financial module until the update is applied.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-5554

Affected Products

Line Client For Ios