Security Advisory

CVE-2019-13096

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-22 16:14:26
Last updated 2024-08-04 23:41:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.