VYPR

by Aeroadmin

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-8894Hig0.538.10.01Jul 2, 2017AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can hijack an update via man-in-the-middle in order to execute code in the machine.
CVE-2017-8893Hig0.497.50.00Jul 2, 2017AeroAdmin 4.1 uses a function to copy data between two pointers where the size of the data copied is taken directly from a network packet. This can cause a buffer overflow and denial of service.