CVE-2023-45220

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 25, 2023
Updated: Nov 6, 2023
CWE ID 306

Summary

CVE-2023-45220: A vulnerability affects the Android Client application. When users manually enroll the app with a server IP address, it retrieves sensitive information, such as IP addresses and credentials, using insecure HTTP instead of HTTPS. Regrettably, this non-configurable setting leaves the data susceptible to interception and potential misuse.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share