Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgq7-cw57-j447

Опубликовано: 28 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

EPSS

Процентиль: 17%
0.00054
Низкий

3.9 Low

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 3.9
nvd
почти 4 года назад

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

EPSS

Процентиль: 17%
0.00054
Низкий

3.9 Low

CVSS3

Дефекты

CWE-922