8.1
CVE-2017-11130
- EPSS 0.4%
- Veröffentlicht 01.08.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure confidentiality. In the whole protocol, no integrity or authenticity checks are done. Therefore man-in-the-middle attackers can conduct replay attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stashcat ≫ Heinekingmedia SwPlatform android Version <= 1.7.5
Stashcat ≫ Heinekingmedia SwEdition web Version <= 0.0.80w
Stashcat ≫ Heinekingmedia SwEdition desktop Version <= 0.0.86w
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.312 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.2 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
http://seclists.org/fulldisclosure/2017/Jul/90