PT-2010-5362 · Wells Fargo · Wells Fargo Mobile
CVE-2010-4214
·
Publicado
2010-11-08
·
Atualizado
2010-11-09
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wells Fargo Mobile application version 1.1
Description
The issue concerns the storage of sensitive information in cleartext, which could allow physically proximate attackers to obtain this information by reading application data. This includes usernames, passwords, and account balances.
Recommendations
For version 1.1, consider removing or securely storing sensitive information, such as usernames, passwords, and account balances, to prevent unauthorized access. As a temporary workaround, restrict physical access to devices with the Wells Fargo Mobile application installed until a secure storage mechanism is implemented.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wells Fargo Mobile