An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-coded DES Cryptographic Key allows an attacker who decodes the application to decrypt transmitted data such as the login username and password.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://advisories.e2security.de/2018/E2SA-2018-01.txt | third party advisory exploit |
https://seclists.org/bugtraq/2018/Oct/3 | mailing list exploit third party advisory |