CVE-2019-7323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
04/02/2019
Last modified:
24/08/2020

Description

GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. The update process relies on cleartext HTTP. The attacker could replace the LogMXUpdater.class file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:logmx:logmx:*:*:*:*:*:*:*:* 7.4.0 (excluding)