Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://gxx777.github.io/Archery_v1.10.0_Cryptographic_API_Misuse_Vulnerability.md | third party advisory |