Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.
References
Configurations
History
10 Jan 2024, 19:30
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:geniecompany:aladdin_connect:*:*:*:*:*:android:*:* | |
References | () https://www.rapid7.com/blog/post/2024/01/03/genie-aladdin-connect-retrofit-garage-door-opener-multiple-vulnerabilities/ - Vendor Advisory | |
CWE | CWE-922 | |
First Time |
Geniecompany
Geniecompany aladdin Connect |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
03 Jan 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-03 20:15
Updated : 2025-06-17 20:15
NVD link : CVE-2023-5879
Mitre link : CVE-2023-5879
JSON object : View
Products Affected
geniecompany
- aladdin_connect
CWE
CWE-922
Insecure Storage of Sensitive Information