The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature is not configurable by the user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published: 2023-10-25T14:15:02.630Z

Updated: 2024-09-11T18:11:14.503Z

Reserved: 2023-10-18T09:35:22.513Z

Link: CVE-2023-45220

cve-icon Vulnrichment

Updated: 2024-08-02T20:14:19.996Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-25T18:17:33.107

Modified: 2023-11-06T14:42:32.330

Link: CVE-2023-45220

cve-icon Redhat

No data.