漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update
Vulnerability Description
eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer before running it. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a crafted update descriptor pointing to an attacker-controlled executable, which the client downloads and executes, resulting in arbitrary code execution on the victim host.
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
下载代码缺少完整性检查
Vulnerability Title
Latvijas Valsts radio un televīzijas centrs eParakstītājs 加密问题漏洞
Vulnerability Description
Latvijas Valsts radio un televīzijas centrs eParakstītājs是Latvijas Valsts radio un televīzijas centrs公司的一款电子签名与身份认证系统。 Latvijas Valsts radio un televīzijas centrs eParakstītājs 1.10.0之前版本存在安全漏洞,该漏洞源于自动更新通道未进行身份验证和完整性保护,接受任意TLS证书,未验证更新描述符的数字签名及安装程序的Authent
CVSS Information
N/A
Vulnerability Type
N/A