These credentials served as part of the application authentication flow
and communication with the mobile application. An attacker could access
unauthorized information.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41278 | Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile application. An attacker could access unauthorized information. |
Solution
Ossur recommends users download Version 1.5.5 or later of the mobile application. The latest version of the application can be obtained through the app store on respective mobile devices. No additional action is required by users.
Workaround
No workaround given by the vendor.
Fri, 17 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jan 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile application. An attacker could access unauthorized information. | |
| Title | Ossur Mobile Logic Application Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-17T17:59:26.276Z
Reserved: 2024-12-17T14:11:48.984Z
Link: CVE-2024-45832
Updated: 2025-01-17T17:49:58.139Z
Status : Received
Published: 2025-01-17T17:15:11.870
Modified: 2025-01-17T17:15:11.870
Link: CVE-2024-45832
No data.
OpenCVE Enrichment
No data.
EUVD