CVE-2020-27181: Konzept-Ix Publixone

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.

Affected products

  • Konzept-Ix Publixone: before 2020.015 (fixed in 2020.015)

Published 2020-10-27. Last modified 2026-06-17.