4.1
CVE-2018-10812
- EPSS 0.03%
- Veröffentlicht 08.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:04
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the app data folder (on iOS).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitpie ≫ Bitcoin Wallet SwPlatformandroid Version <= 3.2.4
Bitpie ≫ Bitcoin Wallet SwPlatformiphone_os Version <= 3.2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.046 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.1 | 0.5 | 3.6 |
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 1.9 | 3.4 | 2.9 |
AV:L/AC:M/Au:N/C:P/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.