Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3j3x-vgx3-q5cg

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.

An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.

EPSS

Процентиль: 37%
0.00161
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.

EPSS

Процентиль: 37%
0.00161
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-311