漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Sensitive date stored in logcat file
Vulnerability Description
Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the information and later on can use the information to monitor and control the user's account and associated devices.
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Eaton Secure connect mobile app 信息泄露漏洞
Vulnerability Description
Eaton Secure connect mobile app v1.7.3及之前版本中存在信息泄露漏洞,该漏洞源于程序将用户登录凭据存储在logcat文件中。攻击者可借助恶意程序利用该漏洞监视和控制用户的帐户以及关联的设备。
CVSS Information
N/A
Vulnerability Type
N/A