Show plain JSON{"containers": {"cna": {"affected": [{"product": "Hickory Smart", "vendor": "Belwith Products, LLC", "versions": [{"lessThanOrEqual": "01.01.43", "status": "affected", "version": "unspecified", "versionType": "custom"}]}], "credits": [{"lang": "en", "value": "This issue was discovered and reported by Deral Heiland of Rapid7. It has been disclosed in accordance with Rapid7's vulnerability disclosure policy (https://www.rapid7.com/disclosure/)."}], "datePublic": "2019-08-01T00:00:00", "descriptions": [{"lang": "en", "value": "An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions."}], "metrics": [{"cvssV3_0": {"attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", "version": "3.0"}}], "problemTypes": [{"descriptions": [{"cweId": "CWE-922", "description": "CWE-922: Insecure Storage of Sensitive Information", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"dateUpdated": "2019-08-22T13:51:36", "orgId": "9974b330-7714-4307-a722-5648477acda7", "shortName": "rapid7"}, "references": [{"tags": ["x_refsource_MISC"], "url": "https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/"}, {"tags": ["x_refsource_MISC"], "url": "https://play.google.com/store/apps/details?id=com.belwith.hickorysmart&hl=en_US"}], "source": {"advisory": "R7-2019-18.1", "discovery": "INTERNAL"}, "title": "Hickory Smart Lock Insecure Storage on Android", "x_generator": {"engine": "Vulnogram 0.0.7"}, "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "cve@rapid7.com", "DATE_PUBLIC": "2019-08-01T13:05:00.000Z", "ID": "CVE-2019-5632", "STATE": "PUBLIC", "TITLE": "Hickory Smart Lock Insecure Storage on Android"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "Hickory Smart", "version": {"version_data": [{"version_affected": "<=", "version_value": "01.01.43"}]}}]}, "vendor_name": "Belwith Products, LLC"}]}}, "credit": [{"lang": "eng", "value": "This issue was discovered and reported by Deral Heiland of Rapid7. It has been disclosed in accordance with Rapid7's vulnerability disclosure policy (https://www.rapid7.com/disclosure/)."}], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions."}]}, "generator": {"engine": "Vulnogram 0.0.7"}, "impact": {"cvss": {"attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", "version": "3.0"}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "CWE-922: Insecure Storage of Sensitive Information"}]}]}, "references": {"reference_data": [{"name": "https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/", "refsource": "MISC", "url": "https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/"}, {"name": "https://play.google.com/store/apps/details?id=com.belwith.hickorysmart&hl=en_US", "refsource": "MISC", "url": "https://play.google.com/store/apps/details?id=com.belwith.hickorysmart&hl=en_US"}]}, "source": {"advisory": "R7-2019-18.1", "discovery": "INTERNAL"}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-04T20:01:51.963Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://play.google.com/store/apps/details?id=com.belwith.hickorysmart&hl=en_US"}]}]}, "cveMetadata": {"assignerOrgId": "9974b330-7714-4307-a722-5648477acda7", "assignerShortName": "rapid7", "cveId": "CVE-2019-5632", "datePublished": "2019-08-22T13:51:36.900485Z", "dateReserved": "2019-01-07T00:00:00", "dateUpdated": "2024-09-16T21:57:21.046Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}