logo

246 Non-encrypted confidential information - DB


Description

The application stores information from user queries within the database that is stored on the device, allowing an attacker to access the information.


Impact

Obtain information from user queries.


Recommendation

Encrypt all sensitive information that is transported or stored within the application according to the organizations policies.


Threat

Unauthenticated attacker with access to the device.


Expected Remediation Time

30 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: L
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: N
  • User interaction: N
  • Confidentiality (VC): L
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/16