PT-2023-12297 · Unknown · Streetside Samourai Wallet

Published

2023-03-03

·

Updated

2023-03-10

·

CVE-2021-36689

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Streetside Samourai Wallet version 0.99.96i
Description An issue in the PinEntryActivity.java file allows attackers to view sensitive information and decrypt data via a brute force attack using a recovered samourai.dat file. The PIN, which is 5 to 8 digits, may be insufficient to prevent such attacks.
Recommendations For version 0.99.96i, consider increasing the PIN length or implementing additional security measures to prevent brute force attacks. As a temporary workaround, restrict access to the samourai.dat file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36689

Affected Products

Streetside Samourai Wallet