6.8
CVSSv2

CVE-2015-4080

Published: 09/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote malicious users to (1) obtain sensitive information by sniffing the network and (2) obtain access to the device by encrypting messages.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kankun smartsocket

Exploits

The Kankun Smart Socket device and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app The communication happens over UDP An attacker on the local network can use the same key to encrypt and send unsolicited commands to the device and hijack it ...