CVE-2017-3194: Pandora
High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
Affected products
- Pandora Pandora: before 8.3.2 (fixed in 8.3.2)
Published 2017-12-16. Last modified 2026-06-17.