PT-2023-30262 · Phlox · Simple Http Server Plus+1

Published

2023-12-27

·

Updated

2024-10-01

·

CVE-2023-46919

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Phlox com.phlox.simpleserver (aka Simple HTTP Server) version 1.8 com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) version 1.8.1-plus
Description The issue is related to a hardcoded encryption key, specifically aKySWb2jjrr4dzkYXczKRt7K, which is an AES key. This key can be extracted by an attacker with physical access to the application's source code or binary, allowing them to decrypt the TLS secret. The threat posed is from a man-in-the-middle attacker who can intercept and potentially modify data during transmission.
Recommendations For Phlox com.phlox.simpleserver (aka Simple HTTP Server) version 1.8, consider regenerating or updating the encryption key to prevent unauthorized access. For com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) version 1.8.1-plus, consider regenerating or updating the encryption key to prevent unauthorized access. As a temporary workaround, restrict access to sensitive data transmitted over the affected server to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-46919

Affected Products

Simple Http Server
Simple Http Server Plus