CVE-2019-7323
04.02.2019, 16:29
GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. The update process relies on cleartext HTTP. The attacker could replace the LogMXUpdater.class file.Enginsight
Vendor | Product | Version |
---|---|---|
logmx | logmx | 𝑥 < 7.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration