Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20989

Опубликовано: 19 апр. 2021
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device initiated remote port-forward channel can be used to connect to the web management interface. Knowledge of authorization credentials to the management interface is required to perform any further actions.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:fibaro:home_center_2_firmware:*:*:*:*:*:*:*:*
Версия до 4.600 (включая)
cpe:2.3:h:fibaro:home_center_2:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:fibaro:home_center_lite_firmware:*:*:*:*:*:*:*:*
Версия до 4.600 (включая)
cpe:2.3:h:fibaro:home_center_lite:-:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01843
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 5.9
github
больше 3 лет назад

Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device initiated remote port-forward channel can be used to connect to the web management interface. Knowledge of authorization credentials to the management interface is required to perform any further actions.

EPSS

Процентиль: 83%
0.01843
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-295
CWE-295