CVE-2023-45220
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 25, 2023
Updated: Nov 6, 2023
CWE ID 306
Summary
CVE-2023-45220: A vulnerability affects the Android Client application. When users manually enroll the app with a server IP address, it retrieves sensitive information, such as IP addresses and credentials, using insecure HTTP instead of HTTPS. Regrettably, this non-configurable setting leaves the data susceptible to interception and potential misuse.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share