Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmqf-hcfv-43rc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.

In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.

EPSS

Процентиль: 79%
0.01202
Низкий

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 8.1
nvd
почти 5 лет назад

In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.

EPSS

Процентиль: 79%
0.01202
Низкий

Дефекты

CWE-319