PT-2012-5060 · Sand Studio · Airdroid

Publicado

2012-07-26

·

Atualizado

2012-07-27

·

CVE-2012-3886

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions AirDroid version 1.0.4 beta
Description The issue allows remote attackers to obtain cleartext data by exploiting the use of the MD5 algorithm for values in the checklogin key parameter and 7bb cookie. This can be achieved by sniffing the local wireless network and then conducting either a brute-force attack or a rainbow-table attack.
Recommendations For AirDroid version 1.0.4 beta, consider updating the authentication mechanism to use a more secure algorithm, and restrict access to sensitive data until a fix is applied. As a temporary workaround, restrict access to the wireless network to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3886

Produtos afetados

Airdroid