SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-5879

This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.

MEDIUM 6.8EPSS 0.42%

Does this matter?

Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.

Description

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.42% probability · 35th percentile
CISA KEV
Not listed
Weakness
CWE-922
Affected
geniecompany/aladdin connect
Source
cve@rapid7.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.