SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2024-12094

This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database.

MEDIUM 5.4EPSS 0.15%

Does this matter?

Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.

Description

This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. Note: To exploit this vulnerability, the device must be rooted/jailbroken.

CVSS 4.0
5.4 MEDIUMCVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.15% probability · 5th percentile
CISA KEV
Not listed
Weakness
CWE-312
Source
vdisclose@cert-in.org.in

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.