{"api_version":"1","generated_at":"2026-07-23T08:12:24+00:00","cve":"CVE-2017-15582","urls":{"html":"https://cve.report/CVE-2017-15582","api":"https://cve.report/api/cve/CVE-2017-15582.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15582","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15582"},"summary":{"title":"CVE-2017-15582","description":"In net.MCrypt in the \"Diary with lock\" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-10-27 20:29:01","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-798","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html","name":"https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Auditing WriteDiary.com (CVE-2017-15581 & CVE-2017-15582)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa","name":"https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Auditing WriteDiary.com (CVE-2017-15581 & CVE-2017-15582)  · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15582","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15582","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"writediary","cpe5":"diary_with_lock","cpe6":"4.72","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T19:57:27.044Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-10-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"In net.MCrypt in the \"Diary with lock\" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-27T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html"},{"tags":["x_refsource_MISC"],"url":"https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-15582","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In net.MCrypt in the \"Diary with lock\" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html","refsource":"MISC","url":"https://1337sec.blogspot.de/2017/10/auditing-writediarycom-cve-2017-15581.html"},{"name":"https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa","refsource":"MISC","url":"https://gist.github.com/anonymous/603b89f864a71426042b167cab557efa"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-15582","datePublished":"2017-10-27T20:00:00.000Z","dateReserved":"2017-10-18T00:00:00.000Z","dateUpdated":"2024-08-05T19:57:27.044Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-10-27 20:29:01","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-798","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:writediary:diary_with_lock:4.72:*:*:*:*:android:*:*","matchCriteriaId":"5BB6A5D8-4DA9-4860-9FA2-AA5989508EA0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15582","Ordinal":"1","Title":"CVE-2017-15582","CVE":"CVE-2017-15582","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15582","Ordinal":"1","NoteData":"In net.MCrypt in the \"Diary with lock\" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.","Type":"Description","Title":"CVE-2017-15582"},{"CveYear":"2017","CveId":"15582","Ordinal":"2","NoteData":"2017-10-27","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15582","Ordinal":"3","NoteData":"2017-10-27","Type":"Other","Title":"Modified"}]}}}