Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fcw-hqq7-pqmf

Опубликовано: 01 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app

EPSS

Процентиль: 5%
0.0002
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.7
nvd
почти 2 года назад

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app

EPSS

Процентиль: 5%
0.0002
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-798