MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
References
Link | Resource |
---|---|
https://0dr3f.github.io/cve/ | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-09-19 16:15
Updated : 2023-09-22 16:45
NVD link : CVE-2023-38356
Mitre link : CVE-2023-38356
CVE.ORG link : CVE-2023-38356
JSON object : View
Products Affected
minitool
- power_data_recovery
CWE
CWE-295
Improper Certificate Validation