Description
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.
Problem types
CWE-522 Insufficiently Protected Credentials
CWE-923 Improper Restriction of Communication Channel to Intended Endpoints
Product status
7.0.9 (semver) before 7.6.3.25808
Credits
Asa Reynolds (SRA)
Rick Console (SRA)
References
sra.io/advisories