7.5

CVE-2017-2748

A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app. HP has no access to customer data as a result of this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Isaac Mizrahi Smartwatch Version 1.0.2.10 SwPlatform iphone_os
Hp ≫ Isaac Mizrahi Smartwatch Version 1.0.201601214 SwPlatform android
Hp ≫ Isaac Mizrahi Smartwatch Version 1.2.2.12 SwPlatform iphone_os
Hp ≫ Isaac Mizrahi Smartwatch Version 1.2.2016040820 SwPlatform android
Hp ≫ Isaac Mizrahi Smartwatch Version 1.3.7 SwPlatform iphone_os
Hp ≫ Isaac Mizrahi Smartwatch Version 1.3.2016052319 SwPlatform android
Hp ≫ Isaac Mizrahi Smartwatch Version 1.4.8 SwPlatform iphone_os
Hp ≫ Isaac Mizrahi Smartwatch Version 1.4.2016072601 SwPlatform android
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.9% 0.77
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://support.hp.com/us-en/document/c05976868
Vendor Advisory