Back

HIGH

Eaton Halo Home Android App Insecure Storage

Published May 22, 2019

Description

The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored OAuth token, thus allowing them to view and change the user's personal information stored in the backend cloud service. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.

Affected products

Remediation

Vendor solution

Users should update their HALO Home app to v1.11.0 or higher via Google Play.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published May 22, 2019
Updated Aug 4, 2024
Reserved Jan 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a