Incomplete in the CWE catalog · 2 CVEs mapped
The product provides or relies on use of HTTP communications when HTTPS is available.
PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.
The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.