The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote attackers to (1) obtain sensitive information by sniffing the network and (2) obtain access to the device by encrypting messages.
References
Configurations
History
21 Nov 2024, 02:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/132210/Kankun-Smart-Socket-Mobile-App-Hardcoded-AES-Key.html - | |
References | () http://www.securityfocus.com/archive/1/535702/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/75057 - | |
References | () https://plus.google.com/109112844319840106704/posts - |
Information
Published : 2015-06-09 14:59
Updated : 2024-11-21 02:30
NVD link : CVE-2015-4080
Mitre link : CVE-2015-4080
CVE.ORG link : CVE-2015-4080
JSON object : View
Products Affected
kankun
- smartsocket
CWE
CWE-310
Cryptographic Issues