CVE-2020-35455

HIGH

Taidii Diibear - Cleartext Storage

Title source: rule
STIX 2.1

Description

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-312
Status published
Products (1)
taidii/diibear 2.4.0
Published Mar 17, 2021
Tracked Since Feb 18, 2026