CVE-2024-6295
Estado: AplazadaBaja (3.9)—
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 3.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-922
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-6295",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-6295",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-06-25T20:36:15.377463Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.9,
"attackVector": "PHYSICAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.3
}
]
},
"affected": [
{
"source": "twcert@cert.org.tw",
"affectedData": [
{
"vendor": "udn",
"product": "udn News App",
"versions": [
{
"status": "affected",
"version": "earlier",
"lessThan": "4.20.1",
"versionType": "custom"
}
],
"platforms": [
"Android"
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:udn:udn_news_app:*:*:*:*:*:*:*:*"
],
"vendor": "udn",
"product": "udn_news_app",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.20.1",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-06-25T03:15:10.740",
"references": [
{
"url": "https://www.twcert.org.tw/en/cp-139-7895-80dac-2.html",
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-7894-aebd8-1.html",
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/en/cp-139-7895-80dac-2.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-7894-aebd8-1.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"description": [
{
"lang": "en",
"value": "CWE-922"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn."
},
{
"lang": "es",
"value": "La aplicación para Android udn News almacena la sesión del usuario sin cifrar en la base de datos local cuando el usuario inicia sesión en la aplicación. Una APP maliciosa o un atacante con acceso físico al dispositivo Android puede recuperar esta sesión y utilizarla para iniciar sesión en la APP de noticias y otros servicios proporcionados por la udn."
}
],
"lastModified": "2026-06-17T08:17:43.780",
"sourceIdentifier": "twcert@cert.org.tw"
}