CVE-2022-34910

MEDIUM

aremis_4_nomads < 1.5.1 - Cleartext Storage of Sensitive Information

Title source: llm
STIX 2.1

Description

An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve the passwords of other users that used the same device.

Scores

CVSS v3 4.1
EPSS 0.0013
EPSS Percentile 2.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
aremis/aremis_4_nomads < 1.5.1
Published Feb 27, 2023
Tracked Since Feb 18, 2026