CVE-2020-6653 - CVE House
Back to Database
Status published Low CVE-2020-6653

Sensitive date stored in logcat file

Vulnerability Description

Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the information and later on can use the information to monitor and control the user's account and associated devices.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-6653

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Eaton would like to thank Vishal Bharad for working with Eaton and helping Eaton in releasing more robust and secure products.

Affected Vendor

Affected Software

Secure Connect Mobile App
Vulnerable Versions:
unspecified

Timeline

Official Publish: August 12th, 2020
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)