Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://blogs.akamai.com/sitr/ | vendor advisory |
https://blogs.akamai.com/2020/08/enterprise-application-access-client-eaa-vulnerability-cve-2019-18847.html | vendor advisory |