Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8j4q-8455-qxw3

Опубликовано: 04 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.

The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.

EPSS

Процентиль: 54%
0.00309
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.

CVSS3: 7.1
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения контроллеров Nexx Garage Door Controller (NXG-100B, NXG-200), Nexx Smart Plug (NXPG-100W), Nexx Smart Alarm (NXAL-100), связанная с недостаточной проверкой входных данных, позволяющая нарушителю получить информацию, предназначенную для других устройств

EPSS

Процентиль: 54%
0.00309
Низкий

5.3 Medium

CVSS3