Vulnerabilities > CVE-2019-5954 - Unspecified vulnerability in Jreast JR East Japan 1.0/1.2.0/1.2.4

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
jreast
critical

Summary

JR East Japan train operation information push notification App for Android version 1.2.4 and earlier allows remote attackers to bypass access restriction to obtain or alter the user's registered information via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Jreast
3