In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html | issue tracking third party advisory |
https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa | issue tracking third party advisory |