Global TV Unencrypted Analytics

2020.02.20
Credit: David Coomber
Risk: Low
Local: No
Remote: Yes
CWE: CWE-200


Ogólna skala CVSS: 4/10
Znaczenie: 2.9/10
Łatwość wykorzystania: 8/10
Wymagany dostęp: Zdalny
Złożoność ataku: Niska
Autoryzacja: Jednorazowa
Wpływ na poufność: Częściowy
Wpływ na integralność: Brak
Wpływ na dostępność: Brak

Global TV Android & iOS Applications - Unencrypted Analytics (CVE-2020-8506) -- https://www.info-sec.ca/advisories/Global-TV.html Overview "Watch the latest full episodes of your favourite Global shows" (https://play.google.com/store/apps/details?id=com.shawmedia.smglobal) (https://apps.apple.com/ca/app/global-tv/id404050595) Issue The Global TV Android & iOS applications (Android version 2.3.2 and below, iOS version 4.7.5 and below) sends potentially sensitive information such as device model & resolution, mobile carrier, days since first use, days since last use, total number of app launches, number of app launches since upgrade, and previous app session length, unencrypted to both first (CNAME to third) and third party sites (Adobe Experience Cloud, ScorecardResearch). Impact An attacker who can monitor network traffic could capture potentially sensitive information about the user's device and viewing habits without their knowledge. Timeline October 7, 2019 - Provided additional information about my research on unencrypted analytics to Apple via product-security@apple.com October 17, 2019 - Attempted to obtain a security contact via a Global TV support form October 22, 2019 - Provided the details to the Adobe PSIRT via psirt@adobe.com and asked for assistance contacting the vendor November 14, 2019 - Attempted to obtain a security contact via an email to mobilesupport@globaltv.com Solution The Global TV Android & iOS applications as of February 4, 2020 are affected. CVE-ID: CVE-2020-8506


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top