PT-2015-7104 · Impero · Impero Education Pro

Slipstream/Rol

·

Published

2015-09-14

·

Updated

2015-09-16

·

CVE-2015-5997

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Impero Education Pro versions prior to 5105
Description The issue allows remote attackers to obtain plaintext data by sniffing the network for ciphertext data, due to the use of a hardcoded CBC key and initialization vector derived from a hash of the Imp3ro string.
Recommendations For versions prior to 5105, update to version 5105 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-5997

Affected Products

Impero Education Pro