CVE-2017-13101: Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption
Published Aug 15, 2018
·Updated
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
Affected Software
1 affected component
TikTok Musical.ly Iphone Os=6.1.6
Event History
Aug 15, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-13101?
CVE-2017-13101 is classified as a serious vulnerability due to the use of a hard-coded encryption key.
2
How do I fix CVE-2017-13101?
To fix CVE-2017-13101, update to a version of the application that does not use a hard-coded encryption key.
3
What type of data is affected by CVE-2017-13101?
CVE-2017-13101 affects any data encrypted with the hard-coded key within the Musical.ly app.
4
Who is affected by CVE-2017-13101?
Users of the Musical.ly application version 6.1.6 on iOS are affected by CVE-2017-13101.
5
Can CVE-2017-13101 lead to data breaches?
Yes, because the hard-coded key can be accessed by anyone, CVE-2017-13101 poses a risk of data breaches.