PT-2018-5482 · Google · Live.Me

Published

2018-08-15

·

Updated

2019-10-09

·

CVE-2017-13107

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Live.me version 3.7.20
Description: The Android application uses a hard-coded key for encryption, which means that data stored using this key can be decrypted by anyone able to access this key.
Recommendations: For version 3.7.20, consider updating the application to a newer version that does not use a hard-coded encryption key, if available. As a temporary workaround, restrict access to sensitive data stored by the application to minimize the risk of unauthorized decryption.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-13107

Affected Products

Live.Me