Skip to content
appaloosa scout logo main rounded
HIGH 7.5

CVE-2017-15582

In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
writediary diary_with_lock Android cpe:2.3:a:writediary:diary_with_lock:4.72:*:*:*:*:android:*:*
View on NVD ↗