漏洞标题
在 Wire 应用中, mandatory 静止加密可以通过绕过(UI)来实现
漏洞描述信息
在Wire应用中,静止状态的强制加密可以被绕过(UI)
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
Mandatory encryption at rest can be bypassed (UI) in Wire app
漏洞描述信息
Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the app will attempt to enable encryption at rest by generating encryption keys via the Secure Enclave, however it will fail silently if no device passcode is set. The user has no indication that encryption at rest is not active since the feature is hidden to them. This issue has been resolved in version 3.70
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
漏洞类别
将资源暴露给错误范围
漏洞标题
Wire 安全漏洞
漏洞描述信息
Wire是个人开发者的一款聊天软件。该软件支持 Web、WindowsiOS、Android、OS X 平台,有群组功能,可以语音通话,发送照片以及其独创性的打招呼方式 PING。 Wire 存在安全漏洞,Wire by Bund 的用户可以通过简单地禁用他们的设备密码来绕过强制的静态加密功能。
CVSS信息
N/A
漏洞类别
其他