CVE-2018-12076 Information
Feb 14, 2021
cve
Description
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated local attacker to access funds within the customer’s MarketCard balance and also could lead to Customer Information Disclosure. The vulnerability is due to lack of proper validation of the UPC bar code present on the MarketCard. An attacker could exploit this vulnerability by generating a copy of a customer’s bar code. An exploit could allow the attacker to access all funds located within the MarketCard or allow unauthenticated disclosure of information.
CVSS Vector
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://sorsnce.com/2018/11/13/announcing-cve-2018-12076/
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.2
Share on: