CVE Vulnerabilities

CVE-2024-42496

Plaintext Storage of a Password

Published: Sep 30, 2024 | Modified: Sep 30, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Potential Mitigations

References