CVE-2019-20469

MEDIUM

One2Track 2019-12-08 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker who has physical access can retrieve all audio files by connecting via a USB cable.

References (3)

Core 3

Scores

CVSS v3 4.6
EPSS 0.0032
EPSS Percentile 23.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-922
Status published
Published Nov 07, 2024
Tracked Since Feb 18, 2026