CVE-2020-25493
11.02.2021, 18:15
Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.Enginsight
Vendor | Product | Version |
---|---|---|
oclean | oclean | 2.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References