6.1

CVE-2022-38117

Juiker app - Hard-coded Credentials

Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juiker ≫ Juiker Version 4.6.0311.1 SwPlatform android
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.19
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 0.9 5.2
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Cert TW 5.5 0.3 5.2
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://www.twcert.org.tw/tw/cp-132-6630-d4d2f-1.html
Third Party Advisory
VDB Entry