Description
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.
References (3)
Core 3
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://tech.feedyourhead.at/content/openelec-remote-code-execution-vulnerability-through-man-in-the-middle
Various Sources x_refsource_misc
https://tech.feedyourhead.at/content/openelec-cve-2017-6445-revisited
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/96580
Scores
CVSS v3
8.1
EPSS
0.0028
EPSS Percentile
51.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-311
CWE-347
Status
published
Products (2)
openelec/openelec
6.0.3
openelec/openelec
7.0.1
Published
Mar 05, 2017
Tracked Since
Feb 18, 2026