eParakstītājs 3.0 for Windows before version
1.10.0 retrieves and executes its automatic updates over a channel that is not
authenticated or integrity-protected. On each launch the application fetches an
update descriptor (XML) over TLS but accepts any TLS certificate (a permissive
TrustManager and a HostnameVerifier that always returns true), does not verify
any digital signature on the update descriptor, and does not verify the
Authenticode signature or a checksum of the downloaded installer before running
it. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a
crafted update descriptor pointing to an attacker-controlled executable, which
the client downloads and executes, resulting in arbitrary code execution on the
victim host.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Latvijas Valsts Radio Un Televīzijas Centrs (lvrtc)
Latvijas Valsts Radio Un Televīzijas Centrs (lvrtc) eparakstītājs 3.0 |
|
| Vendors & Products |
Latvijas Valsts Radio Un Televīzijas Centrs (lvrtc)
Latvijas Valsts Radio Un Televīzijas Centrs (lvrtc) eparakstītājs 3.0 |
Mon, 03 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer before running it. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a crafted update descriptor pointing to an attacker-controlled executable, which the client downloads and executes, resulting in arbitrary code execution on the victim host. | |
| Title | eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update | |
| Weaknesses | CWE-295 CWE-347 CWE-494 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-08-03T10:41:43.673Z
Reserved: 2025-11-27T11:36:47.937Z
Link: CVE-2026-0392
Updated: 2026-08-03T10:41:36.927Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T15:51:40Z