Vulnerability Description
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which allows remote attackers to obtain sensitive information by sniffing the network during LoginActivity or NoteActivity execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Writediary | Diary With Lock | 4.72 |
Related Weaknesses (CWE)
References
- https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.htmlIssue TrackingThird Party Advisory
- https://gist.github.com/anonymous/603b89f864a71426042b167cab557efaIssue TrackingThird Party Advisory
- https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.htmlIssue TrackingThird Party Advisory
- https://gist.github.com/anonymous/603b89f864a71426042b167cab557efaIssue TrackingThird Party Advisory
FAQ
What is CVE-2017-15581?
CVE-2017-15581 is a vulnerability with a CVSS score of 7.5 (HIGH). In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a ...
How severe is CVE-2017-15581?
CVE-2017-15581 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15581?
Check the references section above for vendor advisories and patch information. Affected products include: Writediary Diary With Lock.