AI description
CVE-2024-12604 involves two main vulnerabilities in Tapandsign Technologies' Tap&Sign App, versions prior to 1.025. The application stores sensitive information unencrypted within an environment variable, making it potentially accessible to unauthorized individuals. Additionally, the password recovery mechanism is weak, allowing for exploitation and misuse of related functionalities. Disclosed on December 13, 2024, by Mucahit Ic, this vulnerability allows remote exploitation without authentication. The advisory related to this vulnerability can be found at docs.tapandsign.com. Updating the Tap&Sign App to version 1.025 or later mitigates these vulnerabilities.
- Description
- Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse.This issue affects Tap&Sign App: before V.1.025.
- Source
- iletisim@usom.gov.tr
- NVD status
- Analyzed
- CNA Tags
- exclusively-hosted-service
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 2.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity
- MEDIUM
- Hype score
- Not currently trending
🚨 CVE-2024-12604 🔴 HIGH (7.3) 🏢 Tapandsign Technologies - Tap&Sign App 🏗️ 0 🔗 https://t.co/v1vgadAJqy 🔗 https://t.co/1taVZzc28N #CyberCron #VulnAlert #InfoSec https://t.co/GEWwVQPsOe
@cybercronai
11 Mar 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-12604 Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologie… https://t.co/TC3dfikmEM
@CVEnew
10 Mar 2025
286 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-12604 https://t.co/eFqWi8x5bZ
@mucahic
10 Mar 2025
2975 Impressions
1 Retweet
35 Likes
10 Bookmarks
2 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tapandsign:tap\\&sign:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E38B9DF-2BC7-40C1-A07F-77CEE465DF41",
"versionEndExcluding": "1.025"
}
],
"operator": "OR"
}
]
}
]