CVE-2016-6547
13.07.2018, 20:29
The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.Enginsight
Vendor | Product | Version |
---|---|---|
nutspace | nut_mobile | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-313 - Cleartext Storage in a File or on DiskThe application stores sensitive information in cleartext in a file, or on disk.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References