Fibaro
Fibaro Home Center Lite Firmware: vulnerabilidades y CVE
Fibaro Home Center Lite Firmware tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-20992 | Alta (7.5) | 1.4% | — | 19 abr 2021 | In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions,… |
| CVE-2021-20991 | Alta (8.8) | 5.4% | — | 19 abr 2021 | In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability. |
| CVE-2021-20990 | Alta (7.5) | 3.4% | — | 19 abr 2021 | In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a… |
| CVE-2021-20989 | Media (5.9) | 2.0% | — | 19 abr 2021 | Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using… |