SB2024042410 - MitM attack in MicroWorld Technologies eScan



SB2024042410 - MitM attack in MicroWorld Technologies eScan

Published: April 24, 2024

Security Bulletin ID SB2024042410
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cleartext transmission of sensitive information (CVE-ID: N/A)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to software uses insecure communication channel within the software update functionality. A remote attacker with ability to intercept network traffic can perform MitM attack during software update and swap the update package with malicious files.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install update from vendor's website.