CVE-2017-2748
Summary
| CVE | CVE-2017-2748 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-27 17:29:00 UTC |
| Updated | 2019-03-29 16:39:00 UTC |
| Description | A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app. HP has no access to customer data as a result of this issue. |
Risk And Classification
Problem Types: CWE-254
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hp | Isaac Mizrahi Smartwatch | 1.0.2.10 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.0.201601214 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.2.2.12 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.2.2016040820 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.3.2016052319 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.3.7 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.4.2016072601 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.4.8 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.0.2.10 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.0.201601214 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.2.2.12 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.2.2016040820 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.3.2016052319 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.3.7 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.4.2016072601 | All | All | All |
| Application | Hp | Isaac Mizrahi Smartwatch | 1.4.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HPSBGN03565 rev.1 - Unsecure (http) Transactions in Isaac Mizrahi Smartwatch Mobile App | HP® Customer Support | CONFIRM | support.hp.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.