Lucene search

K
kasperskyKaspersky LabKLA10054
HistoryJun 04, 2008 - 12:00 a.m.

KLA10054 ACE vulnerability in Akamai Download Manager

2008-06-0400:00:00
Kaspersky Lab
threats.kaspersky.com
30

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.16

Percentile

96.0%

CRLF injection vulnerability was found in the Akamai Download Manager. By using this vulnerability spiteful abuser can execute arbitrary code. This vulnerability can be exploited from network at point related to unknown. Via specially designed URL.

Original advisories

vulnerability description

Exploitation

Public exploits exist for this vulnerability.

Related products

Akamai-Download-Manager-ActiveX-Control

CVE list

CVE-2008-1770 critical

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Akamai Download Manager 2 versions 2.2.3.5 and earlier

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.16

Percentile

96.0%