CyberRota Analysis
AI-GeneratedThe local .NET backend of Progress Software Fiddler Everywhere 8.0.2 is vulnerable due to missing authentication, enabling unauthenticated local attackers to generate OAuth tokens and access the machine-in-the-middle root certificate via an unsecured localhost HTTP and SignalR RPC channel. This vulnerability poses a significant risk as it could lead to unauthorized access and potential manipulation of network traffic. Organizations using this version of Fiddler Everywhere should prioritize remediation to mitigate the risk of local exploitation.
Original NVD Description
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.