VulnerabilityModified
CVE-2023-5879
This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.
MEDIUM 6.8EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-922
- Affected
- geniecompany/aladdin connect
- Source
- cve@rapid7.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.