Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf96-wwv9-c857

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-327