CVE-2018-5298
Summary
| CVE | CVE-2018-5298 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-08 08:29:00 UTC |
| Updated | 2018-01-31 15:42:00 UTC |
| Description | In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared preferences. An attacker can gain access to locally stored user data more easily by leveraging access to the preferences XML file. |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pg | Oral-b App | 5.0.0 | All | All | All |
| Application | Pg | Oral-b App | 5.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Auditing the Oral-B App (v5.0.0) | MISC | 1337sec.blogspot.de | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.