CVE-2019-5626
Summary
| CVE | CVE-2019-5626 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-22 18:29:00 UTC |
| Updated | 2020-10-16 15:37:00 UTC |
| Description | The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user activity). This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bluecats | Bluecats Reveal | All | All | All | All |
| Application | Bluecats | Bluecats Reveal | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities Disclosed for Eaton and BlueCats IoT Devices | MISC | blog.rapid7.com | Exploit, Third Party Advisory |
| BlueCats Reveal - Apps on Google Play | MISC | play.google.com | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This vulnerability was discovered by Rapid7 researcher Deral Heiland.
There are currently no legacy QID mappings associated with this CVE.