AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-27768

MEDIUM · CVSS 6.3 EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-05-12 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.3. It affects Android.

CVE
CVE-2021-27768
Severity
MEDIUM
CVSS
6.3
EPSS
0.32%
Android

Original NVD Description

Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in 'transparent' mode while a certificate with an invalid hostname was active. The Android application was found to have hostname verification issues during the server setup and login flows; however, the application did not process requests post-login.

Related CVEs

Other vulnerabilities affecting the same vendor(s)