PT-2023-30262 · Phlox · Simple Http Server Plus+1

CVE-2023-46919

·

Publicado

2023-12-27

·

Atualizado

2024-10-01

CVSS v3.1

6.3

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Phlox com.phlox.simpleserver (aka Simple HTTP Server) version 1.8 com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) version 1.8.1-plus
Description The issue is related to a hardcoded encryption key, specifically aKySWb2jjrr4dzkYXczKRt7K, which is an AES key. This key can be extracted by an attacker with physical access to the application's source code or binary, allowing them to decrypt the TLS secret. The threat posed is from a man-in-the-middle attacker who can intercept and potentially modify data during transmission.
Recommendations For Phlox com.phlox.simpleserver (aka Simple HTTP Server) version 1.8, consider regenerating or updating the encryption key to prevent unauthorized access. For com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) version 1.8.1-plus, consider regenerating or updating the encryption key to prevent unauthorized access. As a temporary workaround, restrict access to sensitive data transmitted over the affected server to minimize the risk of exploitation.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46919

Produtos afetados

Simple Http Server
Simple Http Server Plus