CVE-2023-5879 Vulnerability Details

  /     /     /  

CVE-2023-5879 Metadata Quick Info

CVE Published: 03/01/2024 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: rapid7 | Vendor: The Genie Company | Product: Aladdin Connect Mobile Application
Status : PUBLISHED

CVE-2023-5879 Description

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users\' clear text authentication credentials.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-922
CWE Name: CWE-922 Insecure Storage of Sensitive Information
Source: The Genie Company

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-37
CAPEC Description: CAPEC-37 Retrieve Embedded Sensitive Data


Source: NVD (National Vulnerability Database).