CVE-2022-1716

Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.
References
Link Resource
http://www.kitetech.co/keepmynotes Product Vendor Advisory
https://fluidattacks.com/advisories/tyler/ Exploit Third Party Advisory
http://www.kitetech.co/keepmynotes Product Vendor Advisory
https://fluidattacks.com/advisories/tyler/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:kitetech:keep_my_notes:1.80.147:*:*:*:*:android:*:*

History

21 Nov 2024, 06:41

Type Values Removed Values Added
References () http://www.kitetech.co/keepmynotes - Product, Vendor Advisory () http://www.kitetech.co/keepmynotes - Product, Vendor Advisory
References () https://fluidattacks.com/advisories/tyler/ - Exploit, Third Party Advisory () https://fluidattacks.com/advisories/tyler/ - Exploit, Third Party Advisory

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-287 NVD-CWE-Other

Information

Published : 2022-06-02 18:15

Updated : 2024-11-21 06:41


NVD link : CVE-2022-1716

Mitre link : CVE-2022-1716

CVE.ORG link : CVE-2022-1716


JSON object : View

Products Affected

kitetech

  • keep_my_notes