Adobe AIR <= 22.0.0.153 Android Applications Runtime Analytics MitM (APSB16-31)

high Nessus Plugin ID 93523

Synopsis

The remote Windows host has a browser plugin installed that is affected by a man-in-the-middle vulnerability.

Description

The version of Adobe AIR installed on the remote Windows host is prior or equal to version 22.0.0.153. It is, therefore, affected by a man-in-the-middle (MitM) vulnerability due to the cleartext transmission of runtime analytics for AIR applications on Android. A MitM attacker can exploit this to disclose or tamper with the runtime analytics.

Note that Nessus has not tested for this issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Adobe AIR version 23.0.0.257 or later.

See Also

https://helpx.adobe.com/security/products/air/apsb16-31.html

Plugin Details

Severity: High

ID: 93523

File Name: adobe_air_apsb16-31.nasl

Version: 1.9

Type: local

Agent: windows

Family: Windows

Published: 9/15/2016

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2016-6936

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:air

Required KB Items: SMB/Adobe_AIR/Version, SMB/Adobe_AIR/Path

Exploit Ease: No known exploits are available

Patch Publication Date: 9/13/2016

Vulnerability Publication Date: 9/13/2016

Reference Information

CVE: CVE-2016-6936

BID: 92926