Missing Encryption of Sensitive Data in Kaspersky Internet Security - CVE-2017-12817

 

Missing Encryption of Sensitive Data in Kaspersky Internet Security - CVE-2017-12817

Published: August 25, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38422
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12817
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.


Affected software

Kaspersky Internet Security

How to mitigate CVE-2017-12817

Install update from vendor's website.


External References

Related Security Bulletins