Required CVE Record Information
Description
The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.
Credits
- Thanks to Deral Heiland and Adam Compton of Rapid7, Inc. for reporting this vulnerability.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- kb.cert.org: VU#974055 third-party-advisoryx_transferred
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/ x_transferred
- securityfocus.com: 93875 vdb-entryx_transferred