Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20100

Опубликовано: 02 янв. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:august:august_connect:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:august:august_connect_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:august:august_connect:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00161
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.

EPSS

Процентиль: 37%
0.00161
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-311