« Volver al listado

CVE-2020-13637

Estado: ModificadaAlta (7.5)—

An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext, enabling an attacker (by copying or having access to the local storage database file) to login to the system from any other computer, and get unlimited access to all data in the users's context.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-13637",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-06-17T17:15:10.550",
  "references": [
    {
      "url": "http://www.jvanlaak.de/stashcat.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.jvanlaak.de/stashcat_CWE_312_200527.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.jvanlaak.de/stashcat.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.jvanlaak.de/stashcat_CWE_312_200527.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-312"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext, enabling an attacker (by copying or having access to the local storage database file) to login to the system from any other computer, and get unlimited access to all data in the users's context."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en la aplicación stashcat versiones hasta 3.9.2 para macOS, Windows, Android, iOS y posiblemente otras plataformas. Almacena la clave del cliente, el ID del dispositivo y la clave pública para el cifrado de extremo a extremo en texto sin cifrar, permitiendo a un atacante (copiando o teniendo acceso al archivo de la base de datos de almacenamiento local) iniciar sesión en el sistema desde cualquier otra computadora y obtener acceso ilimitado a todos los datos en el contexto de los usuarios"
    }
  ],
  "lastModified": "2026-06-17T02:53:29.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:heinekingmedia:stashcat:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84B3D363-615C-4E9C-B203-4C5E7623DAC9",
              "versionEndIncluding": "3.9.2"
            },
            {
              "criteria": "cpe:2.3:a:heinekingmedia:stashcat:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8A539DA-EEB9-42EA-AE13-2D561E312624",
              "versionEndIncluding": "3.9.2"
            },
            {
              "criteria": "cpe:2.3:a:heinekingmedia:stashcat:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32FBB669-B311-4369-8858-C9732AD87446",
              "versionEndIncluding": "3.9.2"
            },
            {
              "criteria": "cpe:2.3:a:heinekingmedia:stashcat:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2C9C9CB-68DB-44BC-AA8E-C03DBC9F82C4",
              "versionEndIncluding": "3.9.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}