The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2018-07-06T21:00:00
Updated: 2024-08-06T01:36:27.362Z
Reserved: 2016-08-03T00:00:00
Link: CVE-2016-6538
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-06T21:29:00.217
Modified: 2024-11-21T02:56:18.817
Link: CVE-2016-6538
Redhat
No data.