PT-2018-17980 · Flight Sim · A320-X
Published
2018-02-20
·
Updated
2019-10-03
·
CVE-2018-7259
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flight Sim Labs A320-X installer version 2.0.1.231
Description
The installer sends a user's Google account credentials to "http://installLog.flightsimlabs.com/LogHandler3.ashx" if a pirated serial number has been entered, allowing remote attackers to obtain sensitive information by sniffing the network for cleartext HTTP traffic.
Recommendations
For version 2.0.1.231, update to version 2.0.1.232 to resolve the issue. As a temporary workaround, consider avoiding the use of the installer with potentially pirated serial numbers and restricting network access to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
A320-X