CVE-2018-17500

EUVD-2018-9253
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.9 LOW
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
ibmCNA
2.9 LOW
LOCAL
HIGH
NONE
CVSS:3.0/C:L/AC:H/I:N/AV:L/A:N/PR:N/UI:N/S:U/RL:O/E:U/RC:C