CVE-2024-12604
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD (Secondary)
Description
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse.
This issue affects Tap&Sign App: before V.1.025.
Affected (1)
Products: Tapandsign: Tap&sign
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.025 |
Related CWEs
CWE-312
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CWE-526
Cleartext Storage of Sensitive Information in an Environment Variable
The product uses an environment variable to store unencrypted sensitive information.
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
References (3)
Source: iletisim@usom.gov.tr
Release Notes
Source: iletisim@usom.gov.tr
Timeline
No history available yet.