{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T21:22:36.847","vulnerabilities":[{"cve":{"id":"CVE-2022-38117","sourceIdentifier":"twcert@cert.org.tw","published":"2022-10-24T14:15:50.863","lastModified":"2026-06-17T04:56:08.293","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it."},{"lang":"es","value":"La aplicación Juiker embebe su clave AES en el código fuente. Un atacante físico, después de conseguir el privilegio de root de Android, puede usar la clave AES para descifrar el texto cifrado de usuarios y manipularlo"}],"affected":[{"source":"twcert@cert.org.tw","affectedData":[{"vendor":"Juiker","product":"Juiker app","versions":[{"version":"4.6.0311.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"twcert@cert.org.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.3,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-07T13:33:24.537624Z","id":"CVE-2022-38117","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"twcert@cert.org.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-798"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:juiker:juiker:4.6.0311.1:*:*:*:*:android:*:*","matchCriteriaId":"70D4534E-BD1E-4391-8304-6501024FE375"}]}]}],"references":[{"url":"https://www.twcert.org.tw/tw/cp-132-6630-d4d2f-1.html","source":"twcert@cert.org.tw","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.twcert.org.tw/tw/cp-132-6630-d4d2f-1.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]}]}}]}