Metrics
Affected Vendors & Products
Fri, 28 Feb 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. | The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. Planet Fitness first addressed this vulnerability in version 9.8.12 (released on 2024-07-25) and more recently in version 9.9.13 (released on 2025-02-11). |
Title | Planet Fitness Workouts mobile apps do not properly validate TLS certificates | |
Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 30 Sep 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple iphone Os Google android Planetfitness Planetfitness planet Fitness Workouts |
|
CPEs | cpe:2.3:a:planetfitness:planet_fitness_workouts:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Apple
Apple iphone Os Google android Planetfitness Planetfitness planet Fitness Workouts |
Mon, 23 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Planet Fitness
Planet Fitness planet Fitness Workouts |
|
CPEs | cpe:2.3:a:planet_fitness:planet_fitness_workouts:*:*:*:*:*:*:*:* | |
Vendors & Products |
Planet Fitness
Planet Fitness planet Fitness Workouts |
|
Metrics |
ssvc
|
Mon, 23 Sep 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 23 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. | |
Weaknesses | CWE-295 | |
References |
|

Status: PUBLISHED
Assigner: cisa-cg
Published: 2024-09-23T19:11:39.193Z
Updated: 2025-02-28T17:23:31.051Z
Reserved: 2024-08-07T15:17:44.837Z
Link: CVE-2024-43201

Updated: 2024-09-23T19:24:22.207Z

Status : Modified
Published: 2024-09-23T20:15:04.973
Modified: 2025-02-28T18:15:27.813
Link: CVE-2024-43201

No data.