← back
CVE-2017-13083

CVE-2017-13083

CVSS 5.3 MEDIUMEPSS 1.0%CWE-295CWE-345CWE-347CWE-494
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
Akeo Consulting · Rufus

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →