PT-2019-14800 · Pf+1 · Pf-103+1

Published

2019-12-13

·

Updated

2021-07-21

·

CVE-2019-16732

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Petalk AI (affected versions not specified) PF-103 (affected versions not specified)
Description The issue concerns unencrypted HTTP communications used for firmware upgrades, allowing man-in-the-middle attackers to execute arbitrary code with root user privileges.
Recommendations For Petalk AI, update the firmware to use encrypted communications for upgrades. For PF-103, update the firmware to use encrypted communications for upgrades. As a temporary workaround, consider restricting access to the firmware upgrade process until a secure update method is implemented.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16732

Affected Products

Pf-103
Petalk Ai