RustDesk Client
cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:*:*:*
- <= 1.4.5
A vulnerability in the RustDesk Client's HTTP API that affects multiple platforms, including Windows, MacOS, Linux, iOS, and Android, has been identified. This vulnerability arises from improper certificate validation in the TLS transport modules, allowing for Adversary-in-the-Middle (AiTM) attacks. The issue is linked to the HTTP client in the source file 'hbbs_http/http_client.rs', where the TLS retry routine is set to accept invalid certificates. This vulnerability impacts RustDesk Client versions through 1.4.5.
Exploitation of this vulnerability could lead to Adversary-in-the-Middle attacks, where an attacker could intercept and potentially alter communications between the client and server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.