VulnerabilityModified
CVE-2018-16222
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.
MEDIUM 6.8EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.53% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- ismartalarm/ismartalarm
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/150165/QBee-Camera-iSmartAlarm-Credential-Disclosure.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/2Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/150165/QBee-Camera-iSmartAlarm-Credential-Disclosure.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/2Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.