Описание
Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:juiker:juiker:4.6.0311.1:*:*:*:*:android:*:*
EPSS
Процентиль: 36%
0.0015
Низкий
5.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-798
CWE-798
Связанные уязвимости
CVSS3: 5.5
github
больше 2 лет назад
Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.
EPSS
Процентиль: 36%
0.0015
Низкий
5.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-798
CWE-798