CVE-2023-46919
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K encryption key. The threat is from a man-in-the-middle attacker who can intercept and potentially modify data during transmission.
Phlox com.phlox.simpleserver (también conocido como Simple HTTP Server) 1.8 y com.phlox.simpleserver.plus (también conocido como Simple HTTP Server PLUS) 1.8.1-plus tienen una clave de cifrado aKySWb2jjrr4dzkYXczKRt7K codificada. La amenaza proviene de un atacante intermediario que puede interceptar y potencialmente modificar datos durante la transmisión.
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can extract this key & use it decrypt the TLS secret.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-10-30 CVE Reserved
- 2023-12-27 CVE Published
- 2023-12-28 EPSS Updated
- 2024-11-26 CVE Updated
- 2024-11-26 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/actuator/com.phlox.simpleserver/blob/main/CWE-321.md | 2024-11-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fedirtsapana Search vendor "Fedirtsapana" | Simple Http Server Search vendor "Fedirtsapana" for product "Simple Http Server" | 1.8 Search vendor "Fedirtsapana" for product "Simple Http Server" and version "1.8" | android |
Affected
| ||||||
Fedirtsapana Search vendor "Fedirtsapana" | Simple Http Server Plus Search vendor "Fedirtsapana" for product "Simple Http Server Plus" | 1.8.1-plus Search vendor "Fedirtsapana" for product "Simple Http Server Plus" and version "1.8.1-plus" | android |
Affected
|