PT-2010-5362 · Wells Fargo · Wells Fargo Mobile
Published
2010-11-08
·
Updated
2010-11-09
·
CVE-2010-4214
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wells Fargo Mobile application version 1.1
Description
The issue concerns the storage of sensitive information in cleartext, which could allow physically proximate attackers to obtain this information by reading application data. This includes usernames, passwords, and account balances.
Recommendations
For version 1.1, consider removing or securely storing sensitive information, such as usernames, passwords, and account balances, to prevent unauthorized access. As a temporary workaround, restrict physical access to devices with the Wells Fargo Mobile application installed until a secure storage mechanism is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wells Fargo Mobile