CVE-2018-16222

MEDIUM

iSmartAlarm < 2.0.8 - Cleartext Credential Storage in Configuration File

Title source: llm
STIX 2.1

Description

Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Nov/2

Scores

CVSS v3 6.8
EPSS 0.0053
EPSS Percentile 40.9%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (1)
ismartalarm/ismartalarm < 2.0.8
Published Nov 20, 2018
Tracked Since Feb 18, 2026