CVE-2021-3003
5.3 MEDIUMAgenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-mid...
Published: 2021-05-10 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 5.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
- CWE
- CWE-319
Affected products
| Vendor | Product |
|---|---|
| agenziaentrate | desktop_telematico |
Description
Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-3003
- [Exploit reference]https://fibonhack.github.io/2021/desktop-telematico-mitm-to-rce
- [Vendor advisory]https://telematici.agenziaentrate.gov.it/Main/Desktop.jsp
- [Exploit reference]https://fibonhack.github.io/2021/desktop-telematico-mitm-to-rce
- [Vendor advisory]https://telematici.agenziaentrate.gov.it/Main/Desktop.jsp
Related CVEs
Same CWE
- CVE-2026-9741 — A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryp... (6.5 MEDIUM)
- CVE-2026-45432 — This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management...
- CVE-2026-8874 — Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted ... (7.1 HIGH)
- CVE-2026-36610 — Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding (5.9 MEDIUM)
- CVE-2026-7666 — An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15 (3.1 LOW)