8.1
CVSSv3

CVE-2017-6445

Published: 05/03/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openelec openelec 6.0.3

openelec openelec 7.0.1

Exploits

OpenElec versions 603 and 701 suffer from a remote code execution vulnerability ...