Vulnerability CVE-2017-11130


Published: 2017-08-01

Description:
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure confidentiality. In the whole protocol, no integrity or authenticity checks are done. Therefore man-in-the-middle attackers can conduct replay attacks.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
heinekingmedia StashCat Cryptographic Issues
Karsten-Kai KAPn...
02.08.2017

Type:

CWE-345

(Insufficient Verification of Data Authenticity)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Stashcat -> Heinekingmedia 

 References:
http://seclists.org/fulldisclosure/2017/Jul/90

Copyright 2024, cxsecurity.com

 

Back to Top