IM
IronMonkey Threat Research

CVE-2017-9969 MEDIUM

Published: 2018-02-12 | Last Modified: 2026-06-17 | Status: Modified

Description

An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.

Additional Descriptions (1)

Existe una vulnerabilidad de divulgación de información en la aplicación Schneider Electric's IGSS Mobile, en versiones 3.01 y anteriores. Las contraseñas se almacenan en texto claro en la configuración, lo que puede resultar en la exposición de información sensible.

CVSS Metrics

Base Score: 2.1 (LOW)

AV:L/AC:L/Au:N/C:P/I:N/A:N

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-522

Affected Products

Vendor Product Version Update Type
schneider-electric igss_mobile * <built-in method update of dict object at 0x7e6107f3ad40> Application
schneider-electric igss_mobile * <built-in method update of dict object at 0x7e60a88c3680> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:igss_mobile:*:*:*:*:*:android:*:*
Yes cpe:2.3:a:schneider-electric:igss_mobile:*:*:*:*:*:iphone_os:*:*

References

Notification
Message here