Impero Education Pro before 5105 uses a hardcoded CBC key and initialization vector derived from a hash of the Imp3ro string, which makes it easier for remote attackers to obtain plaintext data by sniffing the network for ciphertext data.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/549807 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2015-09-14 07:59
Updated : 2015-09-16 06:07
NVD link : CVE-2015-5997
Mitre link : CVE-2015-5997
JSON object : View
CWE
Products Affected
impero
- impero_education_pro