CVE-2021-32612
Summary
| CVE | CVE-2021-32612 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-16 12:15:00 UTC |
| Updated | 2021-07-12 16:57:00 UTC |
| Description | The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | I-doo | Veryfitpro | 3.2.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| trovent.github.io/security-advisories/TRSA-2105-01/TRSA-2105-01.txt | MISC | trovent.github.io | |
| Security Advisory 2105-01 - Cyber-Sicherheitslösungen aus Deutschland >> Trovent Security GmbH | MISC | trovent.io | |
| Full Disclosure: Trovent Security Advisory 2105-01 / CVE-2021-32612: VeryFitPro unencrypted cleartext transmission of sensitive information | FULLDISC | seclists.org | |
| VeryFitPro - Apps on Google Play | MISC | play.google.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.