Описание
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 digits, which may be insufficient in this situation.
Ссылки
- Third Party Advisory
- ExploitTechnical DescriptionThird Party Advisory
- Third Party Advisory
- ExploitTechnical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:samourai-wallet-android_project:samourai-wallet-android:0.99.96i:*:*:*:*:android:*:*
EPSS
Процентиль: 10%
0.00036
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-521
Связанные уязвимости
CVSS3: 5.5
github
почти 3 года назад
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 digits, which may be insufficient in this situation.
EPSS
Процентиль: 10%
0.00036
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-521