Описание
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.15.206 (исключая)
Одновременно
cpe:2.3:o:logitech:harmony_hub_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:logitech:harmony_hub:-:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02393
Низкий
8.1 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-78
CWE-78
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.
EPSS
Процентиль: 85%
0.02393
Низкий
8.1 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-78
CWE-78