PT-2009-2607 · Eye Fi · Eye-Fi

Published

2009-09-01

·

Updated

2018-10-11

·

CVE-2008-7138

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Eye-Fi version 1.1.2
Description The issue allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce value, which is predictable based on the time of day.
Recommendations For Eye-Fi version 1.1.2, consider disabling the authentication mechanism that relies on snonce values until a patch is available to prevent remote attackers from bypassing authentication.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7138

Affected Products

Eye-Fi