PT-2024-29990 · Unknown · Smart-Tab Android App
Shuto Imai
·
Published
2024-09-30
·
Updated
2024-09-30
·
CVE-2024-42496
CVSS v3.1
2.4
Low
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Smart-tab Android app versions April 2023 or earlier
Description
The issue concerns the storage of passwords in plaintext. If exploited, an attacker with physical access to the device may retrieve credential information and spoof the device to access related external services.
Recommendations
For versions April 2023 or earlier, consider removing or updating the app to prevent potential exploitation, as the plaintext storage of passwords poses a significant risk. As a temporary workaround, restrict access to sensitive information on devices with the affected app until a secure version is installed.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart-Tab Android App