PT-2012-5058 · Sand Studio · Airdroid

Publicado

2012-07-26

·

Atualizado

2012-07-27

·

CVE-2012-3884

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions AirDroid version 1.0.4 beta
Description The issue allows remote attackers to gain access by sniffing the local wireless network and replaying the authentication data. This is due to the implementation of authentication through direct transmission of a password hash over HTTP.
Recommendations For AirDroid version 1.0.4 beta, consider disabling the authentication mechanism that transmits the password hash over HTTP until a secure alternative is implemented. Restrict access to the wireless network to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3884

Produtos afetados

Airdroid