Weak Hashing Vulnerability in Zipato Zipabox Smart Home Controller
CVE-2018-15124

9.8CRITICAL

Key Information:

Vendor
Kaspersky
Vendor
CVE Published:
13 August 2018

Summary

The Zipato Zipabox Smart Home Controller is susceptible to a vulnerability due to the implementation of a weak hashing algorithm. This flaw allows an unauthenticated attacker to extract clear text passwords from the device, potentially enabling unauthorized root access. Users of the affected Zipabox model with System Version -118 should be particularly aware of this issue and take measures to secure their devices against possible exploitation.

Affected Version(s)

Zipato Zipabox Smart Home Controller BOARD REV - 1

Zipato Zipabox Smart Home Controller SYSTEM VERSION -118

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.