CVE-2020-11614
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attacker can perform a man-in-the-middle attack against this connection and replace executable files with malicious versions, which the operating system then executes under the context of the user running Hero Designer.
Reborn Hero Designer de Mids versión 2.6.0.7 descarga el manifiesto de actualización, así como los archivos de actualización, por medio de HTTP en texto sin cifrar. Además, la aplicación no lleva a cabo la comprobación de integridad de los archivos después de la descarga. Un atacante puede realizar un ataque de tipo man-in-the-middle contra esta conexión y reemplazar los archivos ejecutables con versiones maliciosas, que el sistema operativo ejecuta en el contexto del usuario que ejecuta Hero Designer
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-07 CVE Reserved
- 2020-06-11 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/Crytilis/mids-reborn-hero-designer/releases | Release Notes |
URL | Date | SRC |
---|---|---|
https://www.doyler.net/security-not-included/mids-reborn-vulnerabilities | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mids\' Reborn Hero Designer Project Search vendor "Mids\' Reborn Hero Designer Project" | Mids\' Reborn Hero Designer Search vendor "Mids\' Reborn Hero Designer Project" for product "Mids\' Reborn Hero Designer" | 2.6.0.7 Search vendor "Mids\' Reborn Hero Designer Project" for product "Mids\' Reborn Hero Designer" and version "2.6.0.7" | - |
Affected
|