Vulnerabilities > Magicsmotion

DATE CVE VULNERABILITY TITLE RISK
2021-07-15 CVE-2020-12729 Information Exposure vulnerability in Magicsmotion Flamingo 2 Firmware
MagicMotion Flamingo 2 has a lack of access control for reading from device descriptors.
local
low complexity
magicsmotion CWE-200
2.1
2021-07-15 CVE-2020-12730 Cleartext Transmission of Sensitive Information vulnerability in Magicsmotion Flamingo 2 Firmware
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
high complexity
magicsmotion CWE-319
5.3
2021-07-15 CVE-2020-12731 Cleartext Storage of Sensitive Information vulnerability in Magicsmotion Flamingo 2 Firmware
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
network
low complexity
magicsmotion CWE-312
5.0