Vulnerabilities > CVE-2023-5879 - Insecure Storage of Sensitive Information vulnerability in Geniecompany Aladdin Connect 5.65

047910
CVSS 6.8 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
geniecompany
CWE-922

Summary

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.

Vulnerable Configurations

Part Description Count
Application
Geniecompany
2

Common Weakness Enumeration (CWE)