PT-2017-15510 · Google · Files App
Publicado
2017-11-22
·
Atualizado
2019-10-03
·
CVE-2017-2723
CVSS v3.1
6.7
Média
| Vetor | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Files APP versions 7.1.1.308 and earlier
Description
The issue concerns the plaintext storage of users' Safe passwords in the affected software. An attacker with root privilege of an Android system could exploit this to read users' plaintext Safe passwords, resulting in information leak.
Recommendations
For versions 7.1.1.308 and earlier, update to a version that fixes the plaintext storage of users' Safe passwords to prevent information leak.
Correção
Cleartext Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Files App