Vulnerability Description
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Voatz | Voatz | 2020-01-01 |
Related Weaknesses (CWE)
References
- https://blog.voatz.com/?p=1209Vendor Advisory
- https://internetpolicy.mit.edu/wp-content/uploads/2020/02/SecurityAnalysisOfVoatThird Party Advisory
- https://blog.voatz.com/?p=1209Vendor Advisory
- https://internetpolicy.mit.edu/wp-content/uploads/2020/02/SecurityAnalysisOfVoatThird Party Advisory
FAQ
What is CVE-2020-8988?
CVE-2020-8988 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover logi...
How severe is CVE-2020-8988?
CVE-2020-8988 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8988?
Check the references section above for vendor advisories and patch information. Affected products include: Voatz Voatz.