PT-2017-18605 · Aeroadmin · Aeroadmin

Juan Manuel Fernandez

+1

·

Published

2017-07-02

·

Updated

2017-07-07

·

CVE-2017-8894

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AeroAdmin version 4.1
Description The issue concerns the use of an insecure protocol, specifically HTTP, for software updates. This allows an attacker to potentially hijack an update through a man-in-the-middle attack, enabling them to execute code on the machine.
Recommendations For AeroAdmin version 4.1, consider disabling the automatic update feature until a secure update mechanism is implemented, and restrict network access to trusted sources to minimize the risk of exploitation.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8894

Affected Products

Aeroadmin