← Back

CVE-2018-10812

nvd nist
Published: May 8, 2018Modified: Nov 21, 2024

JSON object

Loading...
4.1
Vector
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.5 / Impact: 3.6
Source: NVD

Description

The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the app data folder (on iOS).

Affected (2)

1 product
Bitcoin Wallet
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Bitpie
Up to 3.2.4
Up to 3.2.4

References (3)

Timeline

No history available yet.