PT-2018-18004 · Square Enix · Final Fantasy Xiv
Leo Tokarski
·
Published
2018-05-23
·
Updated
2019-10-03
·
CVE-2018-7295
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Square Enix Final Fantasy XIV versions 4.21 through 4.25
Description
The issue arises from improper enforcement of message integrity during transmission in a communication channel. This allows a man-in-the-middle attacker to steal user credentials. The problem occurs because a session retrieves global.js via http before proceeding to use https.
Recommendations
For versions 4.21 through 4.25, update to Patch 4.3 to resolve the issue. As a temporary workaround, consider restricting access to unsecured http connections to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Final Fantasy Xiv