Weak Hashing Vulnerability in Zipato Zipabox Smart Home Controller
CVE-2018-15124
9.8CRITICAL
Key Information:
- Vendor
- Kaspersky
- Vendor
- CVE Published:
- 13 August 2018
Summary
The Zipato Zipabox Smart Home Controller is susceptible to a vulnerability due to the implementation of a weak hashing algorithm. This flaw allows an unauthenticated attacker to extract clear text passwords from the device, potentially enabling unauthorized root access. Users of the affected Zipabox model with System Version -118 should be particularly aware of this issue and take measures to secure their devices against possible exploitation.
Affected Version(s)
Zipato Zipabox Smart Home Controller BOARD REV - 1
Zipato Zipabox Smart Home Controller SYSTEM VERSION -118
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved