Security readout for executives and security teams
Plain-English summary
CVE-2019-5632 affects the Hickory Smart Android app for smart locks. The app stored sensitive lock-related information in its local database. If someone with local access to the Android device could obtain that database, the information could reportedly be used to control associated locks remotely.
Executive priority
Treat this as a moderate physical-security support issue. Prioritize affected smart-lock deployments where phones are shared, unmanaged, rooted, lost, or used by staff with high-value facility access.
Technical view
The issue is CWE-922 insecure storage of sensitive information in Hickory Smart for Android version 01.01.43 and earlier. CVSS 3.0 is 6.5 with local attack vector, low complexity, low privileges, no user interaction, changed scope, and high confidentiality impact.
Likely exposure
Exposure is limited to users or organizations using Hickory Smart for Android version 01.01.43 or earlier with configured lock devices. The source bundle does not identify iOS, backend services, or other Belwith products as affected.
Exploitation context
The CVE is not listed as KEV, and the provided sources do not establish active exploitation. The meaningful risk is local compromise or access to an Android device or its app data, followed by misuse of sensitive stored lock information.
Researcher notes
Evidence supports insecure local storage of sensitive information in the Android app database. The bundle does not provide a vendor patch statement, exploitation evidence, or detailed affected CPEs. Avoid expanding scope beyond Hickory Smart for Android 01.01.43 and earlier.
Mitigation direction
- Check Belwith or app store guidance for supported fixed versions.
- Upgrade or retire Hickory Smart Android versions 01.01.43 and earlier.
- Re-provision affected locks if app data exposure is suspected.
- Protect enrolled Android devices with MDM, screen lock, and encryption.
- Remove app data from lost, retired, or reassigned devices.
Validation and detection
- Inventory Android devices with Hickory Smart installed.
- Confirm whether installed versions are 01.01.43 or earlier.
- Identify locks paired with any affected Android installation.
- Review lost, rooted, backed-up, or shared devices for exposure risk.
- Ask the vendor to confirm remediation status for deployed versions.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-922: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupDatabase behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-5632 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N24Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
6.5MediumVector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/CVE reference · x_refsource_MISC
- https://play.google.com/store/apps/details?id=com.belwith.hickorysmart&hl=en_USCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Insecure Storage of Sensitive Information
Insecure Storage of Sensitive Information represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
