CVE-2024-53683

MEDIUM

IPA - Info Disclosure

Title source: llm
STIX 2.1

Description

A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use.

Scores

CVSS v3 4.4
EPSS 0.0006
EPSS Percentile 19.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
Ossur/Mobile Logic Application < 1.5.5
Published Jan 17, 2025
Tracked Since Feb 18, 2026