Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-25493

Опубликовано: 11 фев. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:oclean:oclean:2.1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00158
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-327

Связанные уязвимости

github
больше 3 лет назад

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

EPSS

Процентиль: 37%
0.00158
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-327