Home
MEDIUM: 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
Any version before 4.3.4.2
affected
Description
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
Problem types
CWE-345 Insufficient Verification of Data Authenticity
Product status
Any version before 4.3.4.2
Credits
Alexandru Lazar
Radu Basaraba
References
bitdefender.com/...k-kalay-vulnerabilities-and-their-impact/
bitdefender.com/...k-kalay-vulnerabilities-and-their-impact/