Medium severity6.3NVD Advisory· Published Dec 27, 2023· Updated Jun 17, 2026
CVE-2023-46919
CVE-2023-46919
Description
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can extract this key & use it decrypt the TLS secret.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:fedirtsapana:simple_http_server:1.8:*:*:*:*:android:*:*
- cpe:2.3:a:fedirtsapana:simple_http_server_plus:1.8.1-plus:*:*:*:*:android:*:*
- Phlox/Simple HTTP Serverdescription
- Range: 1.8
Patches
Vulnerability mechanics
References
1- github.com/actuator/com.phlox.simpleserver/blob/main/CWE-321.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.