CVE-2016-6548
Summary
| CVE | CVE-2016-6548 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-13 20:29:00 UTC |
| Updated | 2019-10-09 23:19:00 UTC |
| Description | The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nutspace | Nut Mobile | - | All | All | All |
| Application | Nutspace | Nut Mobile | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zizai Tech Nut Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Multiple Bluetooth Low Energy (BLE) Tracker Vulnerabilities | MISC | blog.rapid7.com | Exploit, Third Party Advisory |
| Vulnerability Note VU#402847 - Zizai Tech Nut contains multiple vulnerabilities | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to Deral Heiland and Adam Compton of Rapid7, Inc. for reporting this vulnerability.
There are currently no legacy QID mappings associated with this CVE.