CVE Published: 10/07/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: jpcert |
Vendor: DREAM TRAIN INTERNET INC. |
Product: TONE store App Status : PUBLISHED
CVE-2024-39886 Description
TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.