VulnerabilityModified
CVE-2013-6986
The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by password elements.
LOW 2.1EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by password elements.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- zippyyum/subway ordering for california
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-12/0040.html
- http://osvdb.org/100745
- http://packetstormsecurity.com/files/124330/ZippyYum-3.4-Insecure-Data-Storage.html
- http://seclists.org/fulldisclosure/2013/Dec/39
- http://archives.neohapsis.com/archives/bugtraq/2013-12/0040.html
- http://osvdb.org/100745
- http://packetstormsecurity.com/files/124330/ZippyYum-3.4-Insecure-Data-Storage.html
- http://seclists.org/fulldisclosure/2013/Dec/39
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.