8.1

CVE-2017-6445

Exploit
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openelec ≫ Openelec Version 6.0.3
Openelec ≫ Openelec Version 7.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1% 0.581
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

http://www.securityfocus.com/bid/96580
https://tech.feedyourhead.at/content/openelec-cve-2017-6445-revisited
https://tech.feedyourhead.at/content/openelec-remote-code-execution-vulnerability-through-man-in-the-middle
Third Party Advisory
Exploit
Technical Description