CVE-2019-5634
MEDIUMBelwith-keeler Hickory Smart < 01.01.43 - Log Information Exposure
Title source: ruleDescription
An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile application are logged in a debug log on the Android device at HickorySmartLog/Logs/SRDeviceLog.txt. This information was found stored in the Android device's default USB or SDcard storage paths and is accessible without rooting the device. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/
Product x_refsource_misc
https://play.google.com/store/apps/details?id=com.belwith.hickorysmart&hl=en_US
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
16.0%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Details
CWE
CWE-532
Status
published
Products (1)
belwith-keeler/hickory_smart
< 01.01.43
Published
Aug 22, 2019
Tracked Since
Feb 18, 2026