CVE-2019-15075

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
20/03/2020
Last modified:
21/07/2021

Description

An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and the r)fddEw232f encryption key.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:inextrix:astpp:*:*:*:*:*:*:*:* 4.0.1 (excluding)