Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rcx-w9pg-pvf5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.

The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.

EPSS

Процентиль: 51%
0.00276
Низкий

8.1 High

CVSS3

Дефекты

CWE-311
CWE-347

Связанные уязвимости

CVSS3: 8.1
nvd
почти 9 лет назад

The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.

EPSS

Процентиль: 51%
0.00276
Низкий

8.1 High

CVSS3

Дефекты

CWE-311
CWE-347