PT-2012-5060 · Sand Studio · Airdroid

Published

2012-07-26

·

Updated

2012-07-27

·

CVE-2012-3886

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions AirDroid version 1.0.4 beta
Description The issue allows remote attackers to obtain cleartext data by exploiting the use of the MD5 algorithm for values in the checklogin key parameter and 7bb cookie. This can be achieved by sniffing the local wireless network and then conducting either a brute-force attack or a rainbow-table attack.
Recommendations For AirDroid version 1.0.4 beta, consider updating the authentication mechanism to use a more secure algorithm, and restrict access to sensitive data until a fix is applied. As a temporary workaround, restrict access to the wireless network to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3886

Affected Products

Airdroid