Vulnerability Description
TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackers to possibly access sensitive information via decryption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tvsmotor | Tvs Connect | 4.6.0 |
Related Weaknesses (CWE)
References
- https://github.com/aaravavi/TVS-Connect-Application-VAPTExploitThird Party Advisory
- https://github.com/aaravavi/TVS-Connect-Application-VAPTExploitThird Party Advisory
FAQ
What is CVE-2024-35537?
CVE-2024-35537 is a vulnerability with a CVSS score of 7.5 (HIGH). TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackers to possibly access sensitive information via decryption.
How severe is CVE-2024-35537?
CVE-2024-35537 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-35537?
Check the references section above for vendor advisories and patch information. Affected products include: Tvsmotor Tvs Connect.