First published: Mon Aug 31 2020(Updated: )
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thomsonstb Tht741fta Firmware | =2.2.1 | |
Thomsonstb Tht741fta | ||
Philips Dtr3502bfta Dvb-t2 Firmware | =2.2.1 | |
Philips DTR3502BFTA DVB-T2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11617 is a vulnerability found in the RSS application on THOMSON THT741FTA and Philips DTR3502BFTA DVB-T2 set-top boxes that allows a man-in-the-middle attacker to modify the data delivered to the client.
CVE-2020-11617 has a severity level of 5.9, which is considered medium.
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes are affected by CVE-2020-11617.
CVE-2020-11617 allows a man-in-the-middle attacker to modify data delivered to the client, compromising the integrity and authenticity of the data.
At the moment, there is no known fix for CVE-2020-11617. It is recommended to follow any provided updates or security advisories from the vendor.