Mutual authentication absence and multicast based server detection allow to spoof server and obtain full control under managed network.
vulners.com/securityvulns/securityvulns:doc:7057