PT-2015-7104 · Impero · Impero Education Pro
Slipstream/Rol
·
Published
2015-09-14
·
Updated
2015-09-16
·
CVE-2015-5997
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Impero Education Pro versions prior to 5105
Description
The issue allows remote attackers to obtain plaintext data by sniffing the network for ciphertext data, due to the use of a hardcoded CBC key and initialization vector derived from a hash of the
Imp3ro string.Recommendations
For versions prior to 5105, update to version 5105 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Impero Education Pro