Описание
Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained.
Ссылки
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 8.14.12 (исключая)
cpe:2.3:a:explorance:blue:*:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.0002
Низкий
6.8 Medium
CVSS3
Дефекты
CWE-257
Связанные уязвимости
CVSS3: 6.8
github
10 дней назад
Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained.
EPSS
Процентиль: 5%
0.0002
Низкий
6.8 Medium
CVSS3
Дефекты
CWE-257