2024-12-08 03:06:42 +00:00

142 lines
4.1 KiB
JSON

{
"id": "CVE-2019-14808",
"sourceIdentifier": "cve@mitre.org",
"published": "2019-10-09T16:15:14.420",
"lastModified": "2024-11-21T04:27:24.033",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user changes personal data in his profile tab (e.g., exposure of his birthday) or logs into his account (i.e., exposure of credentials)."
},
{
"lang": "es",
"value": "Se detect\u00f3 un problema en la aplicaci\u00f3n RENPHO versi\u00f3n 3.0.0 para iOS. Transmite datos JSON sin cifrar hacia un servidor sin una comprobaci\u00f3n de integridad, si un usuario cambia datos personales en su pesta\u00f1a de perfil (por ejemplo, exposici\u00f3n de su cumplea\u00f1os) o inicia sesi\u00f3n en su cuenta (es decir, exposici\u00f3n de credenciales)."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.6,
"impactScore": 5.2
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
"baseScore": 4.0,
"accessVector": "NETWORK",
"accessComplexity": "HIGH",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 4.9,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:renpho:renpho:3.0.0:*:*:*:*:iphone_os:*:*",
"matchCriteriaId": "CF5A83CA-E22B-47D3-816E-8AF79EE1253B"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.com/files/154772/RENPHO-3.0.0-Information-Disclosure.html",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://apps.apple.com/us/app/renpho/id1219889310",
"source": "cve@mitre.org",
"tags": [
"Product"
]
},
{
"url": "https://renpho.com/pages/contact-us",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://packetstormsecurity.com/files/154772/RENPHO-3.0.0-Information-Disclosure.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://apps.apple.com/us/app/renpho/id1219889310",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Product"
]
},
{
"url": "https://renpho.com/pages/contact-us",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}