CVE-2017-13101

HIGH

musical.ly 6.1.6 - Use of Hard-coded Encryption Key

Title source: llm
STIX 2.1

Description

Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/787952

Scores

CVSS v3 7.5
EPSS 0.0099
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-798
Status published
Products (1)
tiktok/musical.ly 6.1.6
Published Aug 15, 2018
Tracked Since Feb 18, 2026