VulnerabilityModified
CVE-2016-6548
An attacker can capture these requests and reuse the session token to gain full access the user's account.
CRITICAL 9.8EPSS 3.71%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.71% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- nutspace/nut mobile
- Source
- cret@cert.org
References
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Exploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/402847Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/93877Third Party Advisory, VDB Entry
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Exploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/402847Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/93877Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.