An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve the passwords of other users that used the same device.
References
Link | Resource |
---|---|
https://www.aremis.com/en_GB/welcome | Not Applicable |
https://excellium-services.com/cert-xlm-advisory/CVE-2022-34910 | Third Party Advisory |
Configurations
Information
Published : 2023-02-27 05:15
Updated : 2023-03-07 08:54
NVD link : CVE-2022-34910
Mitre link : CVE-2022-34910
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
aremis
- aremis_4_nomads