{"api_version":"1","generated_at":"2026-07-23T10:20:40+00:00","cve":"CVE-2019-5633","urls":{"html":"https://cve.report/CVE-2019-5633","api":"https://cve.report/api/cve/CVE-2019-5633.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-5633","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-5633"},"summary":{"title":"CVE-2019-5633","description":"An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for iOS, version 01.01.07 and prior versions.","state":"PUBLIC","assigner":"cve@rapid7.com","published_at":"2019-08-22 14:15:00","updated_at":"2020-10-16 14:52:00"},"problem_types":["CWE-922"],"metrics":[],"references":[{"url":"https://apps.apple.com/us/app/hickory-smart/id1189748191","name":"https://apps.apple.com/us/app/hickory-smart/id1189748191","refsource":"MISC","tags":["Product"],"title":"‎Hickory Smart on the App Store","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/","name":"https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/","refsource":"MISC","tags":["Third Party Advisory"],"title":"IoT Security: Hickory Smart Lock Vulnerability Disclosure Details","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-5633","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5633","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"This issue was discovered and reported by Deral Heiland of Rapid7. It has been disclosed in accordance with Rapid7's vulnerability disclosure policy (https://www.rapid7.com/disclosure/).","lang":""}],"nvd_cpes":[{"cve_year":"2019","cve_id":"5633","vulnerable":"1","versionEndIncluding":"01.01.07","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"belwith-keeler","cpe5":"hickory_smart","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@rapid7.com","DATE_PUBLIC":"2019-08-01T13:05:00.000Z","ID":"CVE-2019-5633","STATE":"PUBLIC","TITLE":"Hickory Smart Lock Insecure Storage on iOS"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Hickory Smart","version":{"version_data":[{"version_affected":"<=","version_value":"01.01.07"}]}}]},"vendor_name":"Belwith Products, LLC"}]}},"credit":[{"lang":"eng","value":"This issue was discovered and reported by Deral Heiland of Rapid7. It has been disclosed in accordance with Rapid7's vulnerability disclosure policy (https://www.rapid7.com/disclosure/)."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for iOS, version 01.01.07 and prior versions."}]},"generator":{"engine":"Vulnogram 0.0.7"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-922: Insecure Storage of Sensitive Information"}]}]},"references":{"reference_data":[{"name":"https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/","refsource":"MISC","url":"https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/"},{"name":"https://apps.apple.com/us/app/hickory-smart/id1189748191","refsource":"MISC","url":"https://apps.apple.com/us/app/hickory-smart/id1189748191"}]},"source":{"advisory":"R7-2019-18.2","discovery":"INTERNAL"}},"nvd":{"publishedDate":"2019-08-22 14:15:00","lastModifiedDate":"2020-10-16 14:52:00","problem_types":["CWE-922"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:belwith-keeler:hickory_smart:*:*:*:*:*:iphone_os:*:*","versionEndIncluding":"01.01.07","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"5633","Ordinal":"143254","Title":"CVE-2019-5633","CVE":"CVE-2019-5633","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"5633","Ordinal":"1","NoteData":"An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for iOS, version 01.01.07 and prior versions.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"5633","Ordinal":"2","NoteData":"2019-08-22","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"5633","Ordinal":"3","NoteData":"2019-08-22","Type":"Other","Title":"Modified"}]}}}