exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Programi Bilanc Build 007 Release 014 31.01.2020 Static Key

Programi Bilanc Build 007 Release 014 31.01.2020 Static Key
Posted Dec 18, 2020
Authored by Georg Ph E Heise

Programi Bilanc build 007 release 014 31.01.2020 leaves a static key in source code that any attacker can leverage to decrypt data.

tags | advisory
advisories | CVE-2020-11719
SHA-256 | e8143a10f9abe21e5d7712b11ead70ee3b98e732d5ee78ed8d06fcc8ff14de5f

Programi Bilanc Build 007 Release 014 31.01.2020 Static Key

Change Mirror Download
Programi Bilanc - Build 007 Release 014 31.01.2020 - Broken encryption with guessable static encryption key

===============================================================================

Identifiers

-------------------------------------------------

CVE-2020-11719

Vendor

-------------------------------------------------

Balanc Shpk (https://bilanc.com)

Product

-------------------------------------------------

Programi Bilanc

Affected versions

-------------------------------------------------

Programi Bilanc - Build 007 Release 014 31.01.2020 and possibly below

Credit

-------------------------------------------------

Georg Ph E Heise (@gpheheise) / Lufthansa Industry Solutions (@LHIND_DLH)

Vulnerability summary

-------------------------------------------------

Remote attacker can decrypt data with minimal effort while local attackers can obtain the static key from the source code.

Technical details

------------------------------------------------

Remote attacker can decrypt data with minimal effort as the encryption used is outdated and broken. Local attackers with access to the software can obtain the static key from the source code.

Proof of concept

-------------------------------------------------

Withheld

Solution

-------------------------------------------------

Don’t use the software in its current version & contact vendor for a solution

Timeline

-------------------------------------------------

Date| Status

------------|--------------------

01–APR-2020 | Reported to vendor

30-JUN-2020 | End of 90 days Full Disclosure Time

17-DEZ-2020 | FULL disclosure


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close