{ "id": "CVE-2017-15581", "sourceIdentifier": "cve@mitre.org", "published": "2017-10-27T20:29:00.857", "lastModified": "2024-11-21T03:14:47.947", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "In the \"Diary with lock\" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for \"a personal journal of ... secrets and feelings,\" which allows remote attackers to obtain sensitive information by sniffing the network during LoginActivity or NoteActivity execution." }, { "lang": "es", "value": "En la aplicaci\u00f3n \"Diary with lock\" (tambi\u00e9n conocida como WriteDiary) en su versi\u00f3n 4.72 para Android, no se utiliza ni HTTPS ni otro cifrado para transmitir los datos, a pesar de la documentaci\u00f3n para la que se ha creado el producto \"un diario personal de... secretos y sentimientos\", lo que permite que atacantes remotos obtengan informaci\u00f3n sensible rastreando la red durante la ejecuci\u00f3n de LoginActivity o NoteActivity." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "baseScore": 5.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-311" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:writediary:diary_with_lock:4.72:*:*:*:*:android:*:*", "matchCriteriaId": "5BB6A5D8-4DA9-4860-9FA2-AA5989508EA0" } ] } ] } ], "references": [ { "url": "https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html", "source": "cve@mitre.org", "tags": [ "Issue Tracking", "Third Party Advisory" ] }, { "url": "https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa", "source": "cve@mitre.org", "tags": [ "Issue Tracking", "Third Party Advisory" ] }, { "url": "https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Issue Tracking", "Third Party Advisory" ] }, { "url": "https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Issue Tracking", "Third Party Advisory" ] } ] }