Home

Description

Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker to eavesdrop on and/or tamper with an encrypted communication.

PUBLISHED Reserved 2025-10-29 | Published 2025-11-17 | Updated 2025-11-17 | Assigner jpcert




MEDIUM: 4.8CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

LOW: 2.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

Improper certificate validation

Product status

prior to ver.80.10.00
affected

References

jvn.jp/en/jp/JVN54005037/

cve.org (CVE-2025-60022)

nvd.nist.gov (CVE-2025-60022)

Download JSON