Aller au contenu
appaloosa scout logo main rounded
fr en
HIGH 7.5

CVE-2017-15582

In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
writediary diary_with_lock Android cpe:2.3:a:writediary:diary_with_lock:4.72:*:*:*:*:android:*:*
Voir sur NVD ↗