First published: Thu Jul 15 2021(Updated: )
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iDrive RemotePC | <7.6.48 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34687 has a medium severity rating due to its potential for information disclosure.
To fix CVE-2021-34687, upgrade iDrive RemotePC to version 7.6.48 or later.
CVE-2021-34687 is classified as an information disclosure vulnerability.
Users of iDrive RemotePC on Windows versions prior to 7.6.48 are affected by CVE-2021-34687.
CVE-2021-34687 allows a man-in-the-middle attacker to recover a system's Personal Key during a LAN connection attempt.