PT-2020-16652 · Konzept Ix · Konzept-Ix Publixone

Marius Schwarz

·

Published

2020-10-27

·

Updated

2021-07-21

·

CVE-2020-27181

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions konzept-ix publiXone versions prior to 2020.015
Description The issue concerns a hardcoded AES key in the Java applet of the affected software. This hardcoded key allows attackers to craft password-reset tokens or decrypt server-side configuration files.
Recommendations For versions prior to 2020.015, update to version 2020.015 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27181

Affected Products

Konzept-Ix Publixone