CVE-2017-3214 describes a critical vulnerability in the Milwaukee ONE-KEY Android mobile application where the master token is stored in plaintext within the application's binary. This allows an attacker to easily extract sensitive authentication credentials. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, potentially leading to a complete compromise of confidentiality. The primary impact is unauthorized access to user accounts or associated services. There is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion or media coverage, suggesting a low profile despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:milwaukeetool:one-key:-:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.