CVE-2021-34688
15.07.2021, 14:15
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.Enginsight
Vendor | Product | Version |
---|---|---|
idrive | remotepc | 𝑥 < 7.6.48 |
𝑥
= Vulnerable software versions