QID 630753
Date Published: 2021-11-25
QID 630753: InBody For Android Exposure of Resource to Wrong Sphere Vulnerability
InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerability which may lead to information disclosure only when it works with the body composition analyzer InBody Dial. This may allow an attacker who can connect to the InBody Dial with InBody App may obtain a victim's measurement result measured by InBody Dial.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-20832 to address this issue and obtain more information.
Vendor References
- CVE-2021-20832 -
nvd.nist.gov/vuln/detail/CVE-2021-20832
CVEs related to QID 630753
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-20832 | Android |
|