CVE-2016-6548 Vulnerability Details

  /     /     /  

CVE-2016-6548 Metadata Quick Info

CVE Published: 13/07/2018 | CVE Updated: 06/08/2024 | CVE Year: 2016
Source: certcc | Vendor: Zizai Technology | Product: Tech Nut Mobile Application
Status : PUBLISHED

CVE-2016-6548 Description

The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user\'s authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user\'s account.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-200
CWE Name: CWE-200: Information Exposure
Source: Zizai Technology

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).