CVE-2021-40846

CVE-2021-40846

An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

Source: CVE-2021-40846

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다