Description
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- AppsAnywhere / AppsAnywhere Client1.4.0 – 1.4.0
- AppsAnywhere / AppsAnywhere Client1.4.1 – 1.4.1
- AppsAnywhere / AppsAnywhere Client1.5.1 – 1.5.1
- AppsAnywhere / AppsAnywhere Client1.5.2 – 1.5.2
- AppsAnywhere / AppsAnywhere Client1.6.0 – 1.6.0
- AppsAnywhere / AppsAnywhere Client2.0.0 – 2.0.0
- AppsAnywhere / AppsAnywhere Client1.6.1 – 1.6.1
- AppsAnywhere / AppsAnywhere Client2.0.1 – 2.0.1
- AppsAnywhere / AppsAnywhere Client2.2.0 – 2.2.0