Описание
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:voatz:voatz:2020-01-01:*:*:*:*:android:*:*
EPSS
Процентиль: 56%
0.00342
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-330
Связанные уязвимости
github
больше 3 лет назад
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.
EPSS
Процентиль: 56%
0.00342
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-330