Security Advisory

CVE-2017-8894

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-07-02 17:00:00
Last updated 2024-08-05 16:48:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can hijack an update via man-in-the-middle in order to execute code in the machine.