CVE-2021-3003
Description
Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Desktop Telematico 1.0.0 fetches updates over cleartext HTTP, allowing an on-path attacker to serve malicious files and achieve remote code execution.
Vulnerability
Desktop Telematico version 1.0.0 from Agenzia delle Entrate downloads software updates over cleartext HTTP from the domain jws.agenziaentrate.it. The connection does not enforce TLS, so the integrity of the update payload is not cryptographically protected. The official release history shows that version 1.3.0 (dated 09/10/2025) is available, but the version affected by this flaw is 1.0.0 as identified in the discovery [1][2].
Exploitation
An attacker positioned on the same network as the victim (for example, on a public Wi‑Fi or a shared corporate LAN) can perform a man‑in‑the‑middle attack against the HTTP connection. The attacker intercepts the update request from the desktop client and replaces the legitimate update package with a malicious executable. No additional authentication or user interaction beyond the normal update triggering is required, because the client fetches files from the cleartext endpoint without verifying a digital signature or hash [1].
Impact
A successful attack results in remote code execution (RCE) on the victim’s machine with the privileges of the Desktop Telematico application. In practice, an attacker can deliver malware (e.g., a cryptolocker), steal or encrypt sensitive data held by users such as accountants (commercialisti) or tax‑assistance centres (CAF). The impact is amplified because the software is mandatory for certain professional workflows and is often run on networks where multiple users share Wi‑Fi credentials [1].
Mitigation
The vendor was contacted and patched the issue in a release that became available around February 2021. Users should install version 1.3.0 or later from the official site [2]. If upgrading is not possible, users should ensure the software is obtained only from the official download page and verify the file’s SHA‑256 hash provided on the site (though this workaround does not fix the in‑app update channel). The CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1][2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Agenzia delle Entrate/Desktop Telematicodescription
- Range: = 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- fibonhack.github.io/2021/desktop-telematico-mitm-to-rcemitrex_refsource_MISC
- telematici.agenziaentrate.gov.it/Main/Desktop.jspmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.