Use of hard-coded credentials in Piccoma App for Android and Piccoma App for iOS - CVE-2024-38480

 

Use of hard-coded credentials in Piccoma App for Android and Piccoma App for iOS - CVE-2024-38480

Published: July 1, 2024


Vulnerability identifier: #VU93521
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38480
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can analyze data in the app and obtain API key for an external service.


Affected software

Piccoma App for Android
Piccoma App for iOS

How to mitigate CVE-2024-38480

Install updates from vendor's website.

Piccoma App for Android - update to 6.20.0
Piccoma App for iOS - update to 6.20.0

External References

Related Security Bulletins