VendorsAremisaremis_4_nomadsall versions
Vulnerabilities

Aremis 4 Nomads

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-34909
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an attacker can bypass authentication and retrieve data that is stored in the database.
Published 2023-02-27 · Modified
9.1EPSS 0.005
CVE-2022-34908
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data.
Published 2023-02-27 · Modified
8.2EPSS 0.006
CVE-2022-34910
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve the passwords of other users that used the same device.
Published 2023-02-27 · Modified
5.5EPSS 0.001