CVE-2020-6653

LOW

Eaton Secureconnect < 1.7.3 - Information Disclosure

Title source: rule
STIX 2.1

Description

Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the information and later on can use the information to monitor and control the user's account and associated devices.

Scores

CVSS v3 3.8
EPSS 0.0006
EPSS Percentile 20.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532 CWE-200
Status published
Products (1)
eaton/secureconnect < 1.7.3
Published Aug 12, 2020
Tracked Since Feb 18, 2026