CVE-2017-5249

CRITICAL

Wink Labs' Wink <6.1.0.19 - Info Disclosure

Title source: llm
STIX 2.1

Description

In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0071
EPSS Percentile 48.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-312 CWE-922
Status published
Products (1)
wink/wink < 6.1.0.19
Published Feb 22, 2018
Tracked Since Feb 18, 2026