CVE-2025-2909

Severity CVSS v4.0:
MEDIUM
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
28/03/2025
Last modified:
28/03/2025

Description

The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.