CVE-2019-5627
Summary
| CVE | CVE-2019-5627 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-22 18:29:00 UTC |
| Updated | 2020-10-16 15:38:00 UTC |
| Description | The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the iOS device or compromise it with a malicious app. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities Disclosed for Eaton and BlueCats IoT Devices | MISC | blog.rapid7.com | Exploit, Third Party Advisory |
| BC Reveal on the App Store | MISC | itunes.apple.com | Product, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This vulnerability was discovered by Rapid7 researcher Deral Heiland.
There are currently no legacy QID mappings associated with this CVE.