CVE-2021-32612
HIGH 8.1EPSS 1.1%
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 1.09% chance of exploitation in the next 30 days, 63th percentile
- Published
- 2021-06-16
- Updated
- 2024-08-03
Proof-of-concept exploits (3)
- http://seclists.org/fulldisclosure/2021/Jun/45
- https://trovent.github.io/security-advisories/TRSA-2105-01/TRSA-2105-01.txt
- https://trovent.io/security-advisory-2105-01