Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hj5-hhq7-f54x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared preferences. An attacker can gain access to locally stored user data more easily by leveraging access to the preferences XML file.

In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared preferences. An attacker can gain access to locally stored user data more easily by leveraging access to the preferences XML file.

EPSS

Процентиль: 23%
0.00075
Низкий

7.5 High

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 7.5
nvd
около 8 лет назад

In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared preferences. An attacker can gain access to locally stored user data more easily by leveraging access to the preferences XML file.

EPSS

Процентиль: 23%
0.00075
Низкий

7.5 High

CVSS3

Дефекты

CWE-326