PT-2009-2607 · Eye Fi · Eye-Fi

Publicado

2009-09-01

·

Atualizado

2018-10-11

·

CVE-2008-7138

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Eye-Fi version 1.1.2
Description The issue allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce value, which is predictable based on the time of day.
Recommendations For Eye-Fi version 1.1.2, consider disabling the authentication mechanism that relies on snonce values until a patch is available to prevent remote attackers from bypassing authentication.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7138

Produtos afetados

Eye-Fi