Integrity Check Flaw in Shelly TRV Devices
CVE-2023-42143

5.4MEDIUM

Key Information:

Vendor

Shelly

Vendor
CVE Published:
23 January 2024

What is CVE-2023-42143?

The identified vulnerability in Shelly TRV devices arises from a lack of proper integrity verification, which allows malicious users to redirect the device towards an attacker-controlled server. This server can then deliver manipulated firmware files to the device, leading to unauthorized updates and potential backdoor access. The absence of effective integrity checks increases the risk of exploitation, highlighting the importance of implementing robust security measures for connected devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.