Vulnerability · NVD
CVE-2017-15918
CVE-2017-15918 : high severity (CVSS 7.8). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 7.8
- Exploitation
- 1.2 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.
Attack vector : Local
No user interaction
Show raw CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.15%
above median
percentile 64.7%
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| ignitum |
sera iOS
|
iOS | - | cpe:2.3:a:ignitum:sera:1.2:*:*:*:*:iphone_os:*:* |