Show plain JSON{"id": "CVE-2017-15997", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 2.1, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.8}]}, "published": "2017-10-29T17:29:00.250", "references": [{"url": "https://1337sec.blogspot.de/2017/10/auditing-nq-contacts-backup-restore-11.html", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://1337sec.blogspot.de/2017/10/auditing-nq-contacts-backup-restore-11.html", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-327"}]}], "descriptions": [{"lang": "en", "value": "In the \"NQ Contacts Backup & Restore\" application 1.1 for Android, RC4 encryption is used to secure the user password locally stored in shared preferences. Because there is a static RC4 key, an attacker can gain access to user credentials more easily by leveraging access to the preferences XML file."}, {"lang": "es", "value": "En la aplicaci\u00f3n NQ Contacts Backup & Restore 1.1 para Android, el cifrado RC4 se emplea para proteger la contrase\u00f1a de usuario almacenada localmente en las preferencias compartidas. Ya que hay una clave RC4 est\u00e1tica, un atacante puede obtener acceso a las credenciales de usuario accediendo al archivo de preferencias XML."}], "lastModified": "2024-11-21T03:15:38.247", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:nq:contacts_backup_\\&_restore:1.1:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "A459EF7F-A85D-4ADC-A69D-CD5582703075"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}