PT-2010-5362 · Wells Fargo · Wells Fargo Mobile
Publicado
2010-11-08
·
Atualizado
2010-11-09
·
CVE-2010-4214
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wells Fargo Mobile application version 1.1
Description
The issue concerns the storage of sensitive information in cleartext, which could allow physically proximate attackers to obtain this information by reading application data. This includes usernames, passwords, and account balances.
Recommendations
For version 1.1, consider removing or securely storing sensitive information, such as usernames, passwords, and account balances, to prevent unauthorized access. As a temporary workaround, restrict physical access to devices with the Wells Fargo Mobile application installed until a secure storage mechanism is implemented.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wells Fargo Mobile