CVE Vulnerabilities

CVE-2016-6538

Cleartext Storage in a File or on Disk

Published: Jul 06, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.

Weakness

The product stores sensitive information in cleartext in a file, or on disk.

Affected Software

Name Vendor Start Version End Version
Trackr_bravo_firmware Thetrackr * 2.2.5 (excluding)
Trackr_bravo_firmware Thetrackr * 5.1.6 (excluding)

References