PT-2017-18605 · Aeroadmin · Aeroadmin
Juan Manuel Fernandez
+1
·
Published
2017-07-02
·
Updated
2017-07-07
·
CVE-2017-8894
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AeroAdmin version 4.1
Description
The issue concerns the use of an insecure protocol, specifically HTTP, for software updates. This allows an attacker to potentially hijack an update through a man-in-the-middle attack, enabling them to execute code on the machine.
Recommendations
For AeroAdmin version 4.1, consider disabling the automatic update feature until a secure update mechanism is implemented, and restrict network access to trusted sources to minimize the risk of exploitation.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aeroadmin