VulnerabilityModified
CVE-2020-25493
The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.
HIGH 7.5EPSS 0.89%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327, CWE-798
- Affected
- oclean/oclean
- Source
- cve@mitre.org
References
- https://github.com/c3r34lk1ll3r/decrypt-oclean-trafficExploit, Third Party Advisory
- https://play.google.com/store/apps/details?id=com.yunding.noopsychebrushforeignProduct
- https://github.com/c3r34lk1ll3r/decrypt-oclean-trafficExploit, Third Party Advisory
- https://play.google.com/store/apps/details?id=com.yunding.noopsychebrushforeignProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.