CVE-2021-34687: Medium severity remotepc vulnerability
Published Jul 15, 2021
·Updated
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.
Affected Software
2 affected components
iDrive RemotePC<7.6.48
Microsoft Windows
Event History
Jul 15, 2021
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-34687?
CVE-2021-34687 has a medium severity rating due to its potential for information disclosure.
2
How do I fix CVE-2021-34687?
To fix CVE-2021-34687, upgrade iDrive RemotePC to version 7.6.48 or later.
3
What type of vulnerability is CVE-2021-34687?
CVE-2021-34687 is classified as an information disclosure vulnerability.
4
Who is affected by CVE-2021-34687?
Users of iDrive RemotePC on Windows versions prior to 7.6.48 are affected by CVE-2021-34687.
5
How does CVE-2021-34687 impact security?
CVE-2021-34687 allows a man-in-the-middle attacker to recover a system's Personal Key during a LAN connection attempt.