CVE Feed

    Dashboard / CVE / CVE-2019-5625

    CVE-2019-5625

    The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored OAuth token, thus allowing them to view and change the user's personal information stored in the backend cloud service. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.

    Published:May 22, 2019
    Last Modified:Nov 21, 2024
    EPS:May 22, 2019
    EPSS Score:0.00081
    CVSS Score:7.1

    Affected Products

    Vendor
    Eaton
    Product
    Halo Home

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High