PT-2012-5058 · Sand Studio · Airdroid
Publicado
2012-07-26
·
Atualizado
2012-07-27
·
CVE-2012-3884
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AirDroid version 1.0.4 beta
Description
The issue allows remote attackers to gain access by sniffing the local wireless network and replaying the authentication data. This is due to the implementation of authentication through direct transmission of a password hash over HTTP.
Recommendations
For AirDroid version 1.0.4 beta, consider disabling the authentication mechanism that transmits the password hash over HTTP until a secure alternative is implemented. Restrict access to the wireless network to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Airdroid