6.5
CVE-2021-43171
- EPSS 0.05%
- Veröffentlicht 22.08.2023 19:16:21
- Zuletzt bearbeitet 21.11.2024 06:28:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
E.Foundation ≫ App Lounge SwPlatformandroid Version < 0.19q
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.159 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.