Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mark Loveless

Researcher fromDuo Labs
#22330of 53,632
10Total CVSS
Vulnerabilities · 2
Medium
2
PT-2017-15708
5.0
2017-06-20
Milwaukee · Milwaukee One-Key · CVE-2017-3214
**Name of the Vulnerable Software and Affected Versions** Milwaukee ONE-KEY Android mobile application (affected versions not specified) **Description** The issue concerns the storage of a master token in plaintext within the apk binary of the application. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2017-15709
5.0
2017-06-20
Milwaukee · Milwaukee One-Key · CVE-2017-3215
**Name of the Vulnerable Software and Affected Versions** Milwaukee ONE-KEY Android mobile application (affected versions not specified) **Description** The issue concerns the use of bearer tokens in the Milwaukee ONE-KEY Android mobile application. These tokens have an expiration period of one year and can be combined with a `user id` to perform various user actions. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.