Lucene search

K
cveRapid7CVE-2019-5627
HistoryMay 22, 2019 - 6:29 p.m.

CVE-2019-5627

2019-05-2218:29:01
CWE-522
CWE-922
rapid7
web.nvd.nist.gov
29
cve-2019-5627
ios
bluecats
reveal
security vulnerability
credentials
app cache
base64 encoding
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

25.6%

The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the iOS device or compromise it with a malicious app.

Affected configurations

Nvd
Node
bluecatsbc_revealRange<5.14iphone_os
VendorProductVersionCPE
bluecatsbc_reveal*cpe:2.3:a:bluecats:bc_reveal:*:*:*:*:*:iphone_os:*:*

CNA Affected

[
  {
    "product": "Reveal",
    "vendor": "BlueCats",
    "versions": [
      {
        "status": "affected",
        "version": "before 5.14"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

25.6%

Related for CVE-2019-5627