CVE-2023-5879

MEDIUM

Aladdin Connect Mobile App <5.65.2075 - Info Disclosure

Title source: llm
STIX 2.1

Description

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.

Scores

CVSS v3 6.8
EPSS 0.0018
EPSS Percentile 39.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (1)
geniecompany/aladdin_connect < 5.73
Published Jan 03, 2024
Tracked Since Feb 18, 2026