7.5
CVSSv3

CVE-2017-2748

Published: 27/03/2019 Updated: 29/03/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app. HP has no access to customer data as a result of this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hp isaac mizrahi smartwatch 1.4.2016072601

hp isaac mizrahi smartwatch 1.4.8

hp isaac mizrahi smartwatch 1.2.2016040820

hp isaac mizrahi smartwatch 1.0.2.10

hp isaac mizrahi smartwatch 1.2.2.12

hp isaac mizrahi smartwatch 1.3.7

hp isaac mizrahi smartwatch 1.0.201601214

hp isaac mizrahi smartwatch 1.3.2016052319

Vendor Advisories

Debian Bug report logs - #857560 mbedtls: CVE-2017-2784: Freeing of memory allocated on stack when validating a public key with a secp224k1 curve Package: libmbedcrypto0; Maintainer for libmbedcrypto0 is James Cowgill <jcowgill@debianorg>; Source for libmbedcrypto0 is src:mbedtls (PTS, buildd, popcon) Reported by: James Cow ...
A potential security vulnerability caused by the use of unsecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app HP has no access to customer data as a result of this issue ...