← back
CVE-2017-2912

CVE-2017-2912

CVSS 7.4 HIGHEPSS 0.7%
An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Circle Media · Circle

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →