CVE-2017-13083
18.10.2017, 13:29
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary codeEnginsight
Vendor | Product | Version |
---|---|---|
rufus_project | rufus | 𝑥 ≤ 2.17 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-295 - Improper Certificate ValidationThe software does not validate, or incorrectly validates, a certificate.
- CWE-494 - Download of Code Without Integrity CheckThe product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
References