4.1
CVE-2018-10812
- EPSS 0.17%
- Veröffentlicht 08.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:04
- Erkennungen
The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the app data folder (on iOS).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitpie ≫ Bitcoin Wallet SwPlatform android Version <= 3.2.4
Bitpie ≫ Bitcoin Wallet SwPlatform iphone_os Version <= 3.2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.065 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.1 | 0.5 | 3.6 |
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 1.9 | 3.4 | 2.9 |
AV:L/AC:M/Au:N/C:P/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
https://github.com/edwardz246003/misc/blob/master/Bitpie.md
https://github.com/edwardz246003/misc/blob/master/Bitpie%20CVE-2018-10812..md