Unrated severityNVD Advisory· Published Mar 4, 2022· Updated Aug 4, 2024
CVE-2021-40846
CVE-2021-40846
Description
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Rhinode Trading Paints/Rhinode Trading Paintsdescription
- Range: <=2.0.36
Patches
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- axelp.io/YWDACmitrex_refsource_MISC
- www.tradingpaints.com/page/Privacymitrex_refsource_MISC
News mentions
0No linked articles in our index yet.