PT-2012-5060 · Sand Studio · Airdroid
Published
2012-07-26
·
Updated
2012-07-27
·
CVE-2012-3886
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AirDroid version 1.0.4 beta
Description
The issue allows remote attackers to obtain cleartext data by exploiting the use of the MD5 algorithm for values in the
checklogin key parameter and 7bb cookie. This can be achieved by sniffing the local wireless network and then conducting either a brute-force attack or a rainbow-table attack.Recommendations
For AirDroid version 1.0.4 beta, consider updating the authentication mechanism to use a more secure algorithm, and restrict access to sensitive data until a fix is applied. As a temporary workaround, restrict access to the wireless network to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airdroid