Impact
The DuoxMe Android application stores user credentials in cleartext in versions prior to 4.3.4, allowing an attacker with local device access to recover those credentials and impersonate the account holder. This vulnerability is classified as CWE-312, cleartext storage of sensitive information.
Affected Systems
Affected products are Fermax Electronica S.A.U.'s DuoxMe app for Android. All releases older than version 4.3.4 contain the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is 0.00099 (< 1%) and the issue is not listed in the CISA KEV catalog, indicating a very low exploitation probability and no widespread known exploitation. The attack vector requires local device access, meaning the attacker must physically or otherwise gain direct access to the device to read the stored credentials. Under those conditions, the vulnerability can lead to credential theft and impersonation, posing a moderate risk to affected users.
OpenCVE Enrichment