PT-2017-18605 · Aeroadmin · Aeroadmin

Juan Manuel Fernandez

+1

·

Publicado

2017-07-02

·

Atualizado

2017-07-07

·

CVE-2017-8894

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AeroAdmin version 4.1
Description The issue concerns the use of an insecure protocol, specifically HTTP, for software updates. This allows an attacker to potentially hijack an update through a man-in-the-middle attack, enabling them to execute code on the machine.
Recommendations For AeroAdmin version 4.1, consider disabling the automatic update feature until a secure update mechanism is implemented, and restrict network access to trusted sources to minimize the risk of exploitation.

Exploit

Correção

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8894

Produtos afetados

Aeroadmin