CVE-2024-12604

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 10, 2025
Updated: Mar 19, 2025
CWE ID 640
CWE ID 526
CWE ID 312

Summary

CVE-2024-12604 is a vulnerability affecting the Tap&Sign App by Tapandsign Technologies. The flaw involves the clear-text storage of sensitive information in an environment variable, making it accessible to attackers. This issue is compounded by a weak password recovery mechanism that allows exploitation, enabling unauthorized password resets. The vulnerability, which affects versions of the Tap&Sign App prior to V.1.025, can lead to functionality misuse and potential data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share