CVE-2017-15997

HIGH

NQ Contacts Backup & Restore 1.1 - Use of a Broken or Risky Cryptographic Algorithm

Title source: llm
STIX 2.1

Description

In the "NQ Contacts Backup & Restore" application 1.1 for Android, RC4 encryption is used to secure the user password locally stored in shared preferences. Because there is a static RC4 key, an attacker can gain access to user credentials more easily by leveraging access to the preferences XML file.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-327
Status published
Products (1)
nq/contacts_backup_\&_restore 1.1
Published Oct 29, 2017
Tracked Since Feb 18, 2026