Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://github.com/mooltipass/moolticute/commits/master | third party advisory patch |
https://securiteam.io/2019/10/20/cve-2019-12967-moolticute-improper-access-control/ | third party advisory exploit |