Back to Database
Status published
High
CVE-2017-3194
Pandora iOS app prior to version 8.3.2 fails to properly...
Vulnerability Description
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-3194
Credits & Attribution
No credits recorded in the NVD database.
References
Affected Vendor
Pandora Media, Inc.
View all reports →Affected Software
Pandora iOS App
Vulnerable Versions:
Prior to 8.3.2
Timeline
Official Publish:
December 15th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H