ZeroHour

CVE-2020-6653

CVSS 3.1
3.9 low
EPSS
<1%p18
Published
()
Modified
Description

Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the information and later on can use the information to monitor and control the user's account and associated devices.

Vendors
eaton
Products
secureconnect
Weakness
CWE-200, CWE-532
Vector
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.