CVE-2014-7242: Ms-Ins Sumaho

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obtain sensitive information by leveraging failure to verify SSL/TLS server certificates.

Affected products

  • Ms-Ins Sumaho: up to and including 3.0.0
  • Ms-Ins Sumaho Driving Capability Diagnosis: up to and including 1.2.2

Published 2017-10-18. Last modified 2026-06-17.