PT-2018-4947 · Itrack · Itrack Easy
Adam Compton
+1
·
Published
2018-07-13
·
Updated
2019-10-09
·
CVE-2016-6546
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iTrack Easy mobile application (affected versions not specified)
Description
The issue concerns the storage of account passwords in the iTrack Easy mobile application. Specifically, the application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. Since base64 encoding is considered equivalent to cleartext, this poses a significant security risk.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Itrack Easy