PT-2017-18605 · Aeroadmin · Aeroadmin
Juan Manuel Fernandez
+1
·
Publicado
2017-07-02
·
Atualizado
2017-07-07
·
CVE-2017-8894
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AeroAdmin version 4.1
Description
The issue concerns the use of an insecure protocol, specifically HTTP, for software updates. This allows an attacker to potentially hijack an update through a man-in-the-middle attack, enabling them to execute code on the machine.
Recommendations
For AeroAdmin version 4.1, consider disabling the automatic update feature until a secure update mechanism is implemented, and restrict network access to trusted sources to minimize the risk of exploitation.
Exploit
Correção
HTTP Request/Response Smuggling
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aeroadmin