5
CVSSv2

CVE-2017-15882

Published: 26/10/2017 Updated: 16/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The London Trust Media Private Internet Access (PIA) application prior to 1.3.3.1 for Android allows remote malicious users to cause a denial of service (application crash) via a large VPN server-list file.

Vulnerable Product Search on Vulmon Subscribe to Product

londontrustmedia private internet access

Exploits

The Android application provided by Private Internet Access (PIA) VPN service can be crashed by downloading a large file containing a list of current VPN servers This can be exploited by an MITM attacker via intercepting and replacing this file While the file is digitally signed, it is not served over SSL and the application did not contain logic ...