Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3rh-h76j-wjwq

Опубликовано: 23 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the Toybox.SensorHistory module without permission. A malicious application could call any functions from the Toybox.SensorHistory module without the user's consent and disclose potentially private or sensitive information.

The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the Toybox.SensorHistory module without permission. A malicious application could call any functions from the Toybox.SensorHistory module without the user's consent and disclose potentially private or sensitive information.

EPSS

Процентиль: 33%
0.00134
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.1
nvd
больше 2 лет назад

The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module without the user's consent and disclose potentially private or sensitive information.

EPSS

Процентиль: 33%
0.00134
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-863