AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can hijack an update via man-in-the-middle in order to execute code in the machine.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.tarlogic.com/advisories/Tarlogic-2017-001.txt | Exploit Vendor Advisory | 
| https://www.tarlogic.com/advisories/Tarlogic-2017-001.txt | Exploit Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2017-07-02 17:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-8894
Mitre link : CVE-2017-8894
CVE.ORG link : CVE-2017-8894
JSON object : View
Products Affected
                aeroadmin
- aeroadmin
CWE
                
                    
                        
                        CWE-444
                        
            Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
