CVE-2017-6466 Information
Feb 14, 2021
cve
Description
F-Secure Software Updater 2.20 as distributed in several F-Secure products downloads installation packages over plain http and does not perform file integrity validation after download. Man-in-the-middle attackers can replace the file with their own executable which will be executed under the SYSTEM account. Note that when Software Updater is configured to install updates automatically it checks if the downloaded file is digitally signed by default but does not check the author of the signature. When running in manual mode (default) no signature check is performed.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://seclists.org/fulldisclosure/2017/Mar/28 http://www.securityfocus.com/bid/96784
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: