← Back

CVE-2024-43201

nvd nist
Published: Sep 23, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:U/V:D/RE:L/U:Amber
Show more
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:U/V:D/RE:L/U:AmberShow less
Source: 9119a7d8-5eab-497f-8521-727c672e3725 (Secondary)

Description

The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. Planet Fitness first addressed this vulnerability in version 9.8.12 (released on 2024-07-25) and more recently in version 9.9.13 (released on 2025-02-11).

Affected (1)

1 product
Planet Fitness Workouts
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 9.8.12
Running on/withPlatform Versions
Apple
Iphone Os
All versions
Google
Android
All versions

References (2)

Source: 9119a7d8-5eab-497f-8521-727c672e3725
Product
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitThird Party Advisory

Timeline

No history available yet.