First published: Thu Feb 22 2018(Updated: )
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Wink Wink | <=6.1.0.19 | |
<=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2017-5249.
CVE-2017-5249 has a severity rating of 9.8 (Critical).
The affected software for CVE-2017-5249 is Wink - Smart Home Android app version 6.1.0.19 and prior.
CVE-2017-5249 could allow a remote attacker to obtain sensitive information.
CVE-2017-5249 can be exploited by exploiting the insecure storage of OAuth token.