Lucene search

K
cveMitreCVE-2021-36689
HistoryMar 04, 2023 - 12:15 a.m.

CVE-2021-36689

2023-03-0400:15:15
CWE-521
mitre
web.nvd.nist.gov
28
cve-2021-36689
streetside samourai wallet
pinentryactivity.java
data decryption
brute force attack
information security

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

18.5%

An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 digits, which may be insufficient in this situation.

Affected configurations

Nvd
Node
samourai-wallet-android_projectsamourai-wallet-androidMatch0.99.96iandroid
VendorProductVersionCPE
samourai-wallet-android_projectsamourai-wallet-android0.99.96icpe:2.3:a:samourai-wallet-android_project:samourai-wallet-android:0.99.96i:*:*:*:*:android:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

18.5%

Related for CVE-2021-36689