PT-2018-4939 · Trackr+1 · Bravo Mobile Application+1
Adam Compton
+1
·
Publicado
2018-07-06
·
Atualizado
2019-10-09
·
CVE-2016-6538
CVSS v2.0
3.3
Baixa
| Vetor | AV:A/AC:L/Au:N/C:P/I:N/A:N |
The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bravo Mobile Application
Trackr Bravo Firmware