Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service.
History

Mon, 30 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 08:00:00 +0000

Type Values Removed Values Added
Description Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service.
Weaknesses CWE-256
References
Metrics cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-09-30T07:51:05.883Z

Updated: 2024-09-30T15:46:18.017Z

Reserved: 2024-09-18T23:09:31.873Z

Link: CVE-2024-42496

cve-icon Vulnrichment

Updated: 2024-09-30T15:46:11.740Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-30T08:15:03.553

Modified: 2024-09-30T12:45:57.823

Link: CVE-2024-42496

cve-icon Redhat

No data.