VulnerabilityModified
CVE-2019-6024
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created by the third party.
MEDIUM 6.5EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created by the third party.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- rakuten/rakuma
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN41566067/index.htmlThird Party Advisory, VDB Entry
- https://apps.apple.com/jp/app/furimaapuri-furiru-fril-fasshon/id523497998Product, Release Notes
- https://play.google.com/store/apps/details?id=jp.co.fablic.fril&hl=enProduct
- http://jvn.jp/en/jp/JVN41566067/index.htmlThird Party Advisory, VDB Entry
- https://apps.apple.com/jp/app/furimaapuri-furiru-fril-fasshon/id523497998Product, Release Notes
- https://play.google.com/store/apps/details?id=jp.co.fablic.fril&hl=enProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.