iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.
Threat-Mapped Scoring
Score: 2.3
Priority: P3 - Important (Medium)
S6 – Espionage of Financial Trades
EPSS
Score: 0.00059 Percentile:
0.1878
CVSS Scoring
CVSS v3.1 Score: 5.3
Severity: MEDIUM
Mapped CWE(s)
CWE-327
: Use of a Broken or Risky Cryptographic Algorithm
All CAPEC(s)
CAPEC-20: Encryption Brute Forcing
CAPEC-459: Creating a Rogue Certification Authority Certificate
CAPEC-473: Signature Spoof
CAPEC-475: Signature Spoofing by Improper Validation