Vulnerability Details CVE-2017-5249
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 48.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2017-5249
-
cpe:2.3:a:wink:wink:6.1.0.19