CVE-2020-25493
Last modified
CVE-2020-25493 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oclean | Oclean | 2.1.2 |
References
- http://oclean.comProduct
- https://github.com/c3r34lk1ll3r/decrypt-oclean-trafficExploit, Third Party Advisory
- http://oclean.comProduct
- https://github.com/c3r34lk1ll3r/decrypt-oclean-trafficExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25493?
How severe is CVE-2020-25493?
How do I fix CVE-2020-25493?
Are you affected by CVE-2020-25493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
