CVE-2017-15581
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which allows remote attackers to obtain sensitive information by sniffing the network during LoginActivity or NoteActivity execution.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-311
- Affected
- writediary/diary with lock
- Source
- cve@mitre.org
References
- https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.htmlIssue Tracking, Third Party Advisory
- https://gist.github.com/anonymous/603b89f864a71426042b167cab557efaIssue Tracking, Third Party Advisory
- https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.htmlIssue Tracking, Third Party Advisory
- https://gist.github.com/anonymous/603b89f864a71426042b167cab557efaIssue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.