CVE-2024-42496

LOW

Smart-tab Android <April 2023 - Info Disclosure

Title source: llm
STIX 2.1

Description

Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service.

Scores

CVSS v3 2.4
EPSS 0.0015
EPSS Percentile 34.6%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-256
Status published
Products (1)
TECHNO SUPPORT COMPANY/Smart-tab Android app installed April 2023 or earlier
Published Sep 30, 2024
Tracked Since Feb 18, 2026