ID:71 - Exploit for Man-in-the-middle attack in Northstar Controller - CVE-2017-1000385

 
Main Vulnerability Database Exploits ID:71 - Exploit for Man-in-the-middle attack in Northstar Controller - CVE-2017-1000385

ID:71 - Exploit for Man-in-the-middle attack in Northstar Controller - CVE-2017-1000385

Published: March 18, 2020


Vulnerability identifier: #VU11845
Vulnerability risk: Low
CVE-ID: CVE-2017-1000385
CWE-ID: CWE-300
Exploitation vector: Remote access
Vulnerable software:
Northstar Controller

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to conduct man-in-the-middle attack on the target system.

The weakness exists due to performing RSA decryption and signing operations with the private key of a TLS server. A remote attacker can gain access to potentially sensitive information.

Remediation

Install update from vendor's website.