Description
In the "NQ Contacts Backup & Restore" application 1.1 for Android, RC4 encryption is used to secure the user password locally stored in shared preferences. Because there is a static RC4 key, an attacker can gain access to user credentials more easily by leveraging access to the preferences XML file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-7413 | In the "NQ Contacts Backup & Restore" application 1.1 for Android, RC4 encryption is used to secure the user password locally stored in shared preferences. Because there is a static RC4 key, an attacker can gain access to user credentials more easily by leveraging access to the preferences XML file. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T00:51:39.239Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-15997
No data.
Status : Deferred
Published: 2017-10-29T17:29:00.250
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15997
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD