Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17763

Опубликовано: 19 дек. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 7.6
EPSS Низкий

Описание

SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:liveqos:superbeam:*:*:*:*:*:*:*:*
Версия до 4.1.3 (включая)

EPSS

Процентиль: 72%
0.00709
Низкий

7.5 High

CVSS3

7.6 High

CVSS2

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.

EPSS

Процентиль: 72%
0.00709
Низкий

7.5 High

CVSS3

7.6 High

CVSS2

Дефекты

CWE-311