« Back to list

CVE-2010-4214

Status: ModifiedMedium (4.3)—

The Wells Fargo Mobile application 1.1 for Android stores a username and password, along with account balances, in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2010-4214",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-11-09T01:00:03.053",
  "references": [
    {
      "url": "http://news.cnet.com/8301-27080_3-20021874-245.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://online.wsj.com/article/SB10001424052748703805704575594581203248658.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://viaforensics.com/appwatchdog/wells-fargo-android.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://news.cnet.com/8301-27080_3-20021874-245.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://online.wsj.com/article/SB10001424052748703805704575594581203248658.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://viaforensics.com/appwatchdog/wells-fargo-android.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Wells Fargo Mobile application 1.1 for Android stores a username and password, along with account balances, in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data."
    },
    {
      "lang": "es",
      "value": "La aplicación Wells Fargo Mobile v1.1 para Android almacena el nombre de usuario y la contraseña, junto con los saldos de cuentas, en texto plano, lo que podría permitir a atacantes físicamente próximos obtener información sensible mediante la lectura de datos de aplicación.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:24:22.430",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wellsfargo:wells_fargo_mobile:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BB0B806-3D03-4045-9888-37E1E584C054"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8255F035-04C8-4158-B301-82101711939C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}