Description
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
Problem types
CWE-345 Insufficient Verification of Data Authenticity
Product status
Any version before 4.3.4.2
Credits
Alexandru Lazar
Radu Basaraba
References
bitdefender.com/...k-kalay-vulnerabilities-and-their-impact/