CVE-2024-39886

TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.
Configurations

No configuration.

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN28515217/ - () https://jvn.jp/en/jp/JVN28515217/ -
References () https://tone.ne.jp/vulnerability/14492007.html - () https://tone.ne.jp/vulnerability/14492007.html -

11 Jul 2024, 15:06

Type Values Removed Values Added
CWE CWE-419
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.7

11 Jul 2024, 13:05

Type Values Removed Values Added
Summary
  • (es) La versión 3.4.2 y anteriores de la aplicación TONE store contiene un problema con el canal principal desprotegido. Dado que la aplicación TONE store se comunica con el sitio web de TONE store en texto plano, un ataque man-in-the-middle puede permitir a un atacante obtener y/o alterar las comunicaciones de la aplicación afectada.

10 Jul 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-10 07:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39886

Mitre link : CVE-2024-39886

CVE.ORG link : CVE-2024-39886


JSON object : View

Products Affected

No product.

CWE
CWE-419

Unprotected Primary Channel