CVE-2017-6445

HIGH

Openelec - Missing Encryption

Title source: rule
STIX 2.1

Description

The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.

References (3)

Core 3
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://tech.feedyourhead.at/content/openelec-remote-code-execution-vulnerability-through-man-in-the-middle
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96580

Scores

CVSS v3 8.1
EPSS 0.0028
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-311 CWE-347
Status published
Products (2)
openelec/openelec 6.0.3
openelec/openelec 7.0.1
Published Mar 05, 2017
Tracked Since Feb 18, 2026