PT-2018-5482 · Google · Live.Me
Published
2018-08-15
·
Updated
2019-10-09
·
CVE-2017-13107
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Live.me version 3.7.20
Description:
The Android application uses a hard-coded key for encryption, which means that data stored using this key can be decrypted by anyone able to access this key.
Recommendations:
For version 3.7.20, consider updating the application to a newer version that does not use a hard-coded encryption key, if available. As a temporary workaround, restrict access to sensitive data stored by the application to minimize the risk of unauthorized decryption.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live.Me