PT-2024-28710 · Unknown · Tone Store App
Kodai Karakawa
·
Published
2024-07-10
·
Updated
2024-07-11
·
CVE-2024-39886
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TONE store App versions 3.4.2 and earlier
Description
The issue is related to an unprotected primary channel in the TONE store App, which communicates with the TONE store website in cleartext. This could allow a man-in-the-middle attack, enabling an attacker to obtain and/or alter communications of the affected App.
Recommendations
For versions 3.4.2 and earlier, consider disabling communication with the TONE store website until a secure connection method is implemented to prevent man-in-the-middle attacks. Restrict access to sensitive data within the App to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tone Store App