Sensitive Information Exposure in Vivo Weather Module
CVE-2021-26279

5.9MEDIUM

Key Information:

Vendor

Vivo

Status
Vendor
CVE Published:
17 December 2024

What is CVE-2021-26279?

CVE-2021-26279 is a critical vulnerability affecting the weather module within Vivo products. This vulnerability arises from inadequate handling of certain parameters, which leads to the unintended exposure of sensitive information. Attackers could exploit this flaw to gain unauthorized access to confidential user data, thereby posing significant security risks. Affected users are encouraged to apply security patches released by Vivo to mitigate risks associated with this vulnerability.

Affected Version(s)

Weather Versions earlier than 6.0.3.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.