Vulnerability Description
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse.This issue affects Tap&Sign App: before V.1.025.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tapandsign | Tap\&Sign | < 1.025 |
Related Weaknesses (CWE)
References
- https://docs.tapandsign.com/tap-and-sign/tap-and-sign-v.1.025-surum-notlariRelease Notes
- https://www.usom.gov.tr/bildirim/tr-25-0063Third Party Advisory
FAQ
What is CVE-2024-12604?
CVE-2024-12604 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Rec...
How severe is CVE-2024-12604?
CVE-2024-12604 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-12604?
Check the references section above for vendor advisories and patch information. Affected products include: Tapandsign Tap\&Sign.