Lack of Transport Encryption in Philips Hue Bridge by Philips
CVE-2017-14797
7.5HIGH
What is CVE-2017-14797?
The Philips Hue Bridge BSB002 SW 1707040932 is vulnerable due to a lack of transport encryption in its public API, which allows attackers on the local network to intercept HTTP traffic. This vulnerability enables unauthorized users to capture API keys, effectively bypassing the pushlink protection mechanism and gaining complete control over the connected accessories. Securing API communications is crucial to prevent potential unauthorized access and ensure the integrity of connected devices.