PT-2012-5058 · Sand Studio · Airdroid
Published
2012-07-26
·
Updated
2012-07-27
·
CVE-2012-3884
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AirDroid version 1.0.4 beta
Description
The issue allows remote attackers to gain access by sniffing the local wireless network and replaying the authentication data. This is due to the implementation of authentication through direct transmission of a password hash over HTTP.
Recommendations
For AirDroid version 1.0.4 beta, consider disabling the authentication mechanism that transmits the password hash over HTTP until a secure alternative is implemented. Restrict access to the wireless network to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airdroid