CVE-2017-6445

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
05/03/2017
Last modified:
20/04/2025

Description

The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openelec:openelec:6.0.3:*:*:*:*:*:*:*
cpe:2.3:o:openelec:openelec:7.0.1:*:*:*:*:*:*:*