漏洞标题
Qardio iOS及Android应用 文件或目录可被外部访问
漏洞描述信息
攻击者可能获取固件文件并进行逆向工程,从而导致由Qardio iOS和Android应用程序支持的硬件设备的机密性和完整性受损。
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
漏洞类别
将资源暴露给错误范围
漏洞标题
Qardio iOS and Android applications Files or Directories Accessible to External Parties
漏洞描述信息
An attacker could obtain firmware files and reverse engineer their
intended use leading to loss of confidentiality and integrity of the
hardware devices enabled by the Qardio iOS and Android applications.
CVSS信息
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
漏洞类别
对外部实体的文件或目录可访问