PT-2024-33143 · Ivy Smart · Ivy Smart

Published

2024-10-24

·

Updated

2024-10-25

·

CVE-2024-48545

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IVY Smart version 4.5.0
Description The issue is related to incorrect access control in the firmware update and download processes. This allows attackers to access sensitive information by analyzing the code and data within the APK file.
Recommendations For IVY Smart version 4.5.0, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-48545

Affected Products

Ivy Smart