AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-14487

CRITICAL · CVSS 9.1 EPSS 1.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-12-01 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2017-14487
Severity
CRITICAL
CVSS
9.1
EPSS
1.16%
Android

Original Filing — NVD Description

The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for search responses from the OhMiBod API server and then editing the username, user_id, and token fields in data/data/com.ohmibod.remote2/shared_prefs/OMB.xml.