Metrics
Affected Vendors & Products
Mon, 17 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 17 Mar 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API Handler. The manipulation leads to use of get request method with sensitive query strings. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | BlackVue App API deviceDelete get request method with sensitive query strings | |
Weaknesses | CWE-598 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-17T01:00:07.179Z
Updated: 2025-03-17T13:37:54.918Z
Reserved: 2025-03-15T20:57:44.599Z
Link: CVE-2025-2356

Updated: 2025-03-17T13:32:54.535Z

Status : Received
Published: 2025-03-17T01:15:37.487
Modified: 2025-03-17T01:15:37.487
Link: CVE-2025-2356

No data.