CVE-2024-52614

MEDIUM

Kura Sushi Official App <3.8.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If this vulnerability is exploited, a local attacker may obtain the login ID and password for the affected product.

Scores

CVSS v3 4.0
EPSS 0.0007
EPSS Percentile 20.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-321
Status published
Products (1)
EPARK, Inc./Kura Sushi Official App Produced by EPARK prior to 3.8.5
Published Nov 20, 2024
Tracked Since Feb 18, 2026