CVE-2024-35537
Tvsmotor
CVE-2024-35537 impacts TVS Connect Android and iOS apps. This vulnerability stems from insecure handling of the RSA key pair, potentially enabling attackers to decrypt and access sensitive information. While the CVSS score is 7.5, the SOCRadar Vulnerability Risk Score (SVRS) is 68, indicating a moderate risk and the need for prompt attention. The insecure RSA key handling (CWE-327) allows unauthorized decryption, jeopardizing user data privacy. Given that the vulnerability is tagged as "In The Wild," active exploitation is possible. Immediate patching and updates are crucial to mitigate the risk of sensitive data exposure and maintain user trust in TVS Connect applications. Ignoring this vulnerability could lead to significant data breaches.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.