PT-2012-5058 · Sand Studio · Airdroid

Published

2012-07-26

·

Updated

2012-07-27

·

CVE-2012-3884

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions AirDroid version 1.0.4 beta
Description The issue allows remote attackers to gain access by sniffing the local wireless network and replaying the authentication data. This is due to the implementation of authentication through direct transmission of a password hash over HTTP.
Recommendations For AirDroid version 1.0.4 beta, consider disabling the authentication mechanism that transmits the password hash over HTTP until a secure alternative is implemented. Restrict access to the wireless network to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3884

Affected Products

Airdroid