PT-2020-7932 · Unknown · Ezseed-Transmission

Published

2020-09-01

·

Updated

2020-09-01

·

CVE-2016-1000224

CVSS v3.1

4.2

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ezseed-transmission versions prior to 0.0.15
Description: The issue allows an attacker in a privileged network position to launch a Man-in-the-Middle attack, intercepting a script downloaded over an HTTP connection and potentially replacing it with malicious code. This could completely compromise the system running the affected software.
Recommendations: Update to version 0.0.15 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1000224
GHSA-P788-RJ37-357W

Affected Products

Ezseed-Transmission