TROYANOSYVIRUS
Voltar para CVEs

CVE-2021-36460

HIGH
7.8

Descricao

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

Detalhes CVE

Pontuacao CVSS v3.17.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado4/25/2022
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

veryfitpro_project:veryfitpro

Fraquezas (CWE)

CWE-287

Referencias

http://veryfitpro.com(cve@mitre.org)
http://www.i-doo.cn(cve@mitre.org)
http://veryfitpro.com(af854a3a-2127-422b-91ae-364da2661108)
http://www.i-doo.cn(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/martinfrancois/CVE-2021-36460(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.