Vulnerability Description
Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Agenziaentrate | Desktop Telematico | 1.0.0 |
Related Weaknesses (CWE)
References
- https://fibonhack.github.io/2021/desktop-telematico-mitm-to-rceExploitThird Party Advisory
- https://telematici.agenziaentrate.gov.it/Main/Desktop.jspVendor Advisory
- https://fibonhack.github.io/2021/desktop-telematico-mitm-to-rceExploitThird Party Advisory
- https://telematici.agenziaentrate.gov.it/Main/Desktop.jspVendor Advisory
FAQ
What is CVE-2021-3003?
CVE-2021-3003 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.
How severe is CVE-2021-3003?
CVE-2021-3003 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3003?
Check the references section above for vendor advisories and patch information. Affected products include: Agenziaentrate Desktop Telematico.