Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.
References
Link | Resource |
---|---|
https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-031_homematic.txt | Exploit Mitigation Third Party Advisory |
Configurations
Information
Published : 2018-09-07 15:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-17691
Mitre link : CVE-2017-17691
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
contronics
- homeputer_cl_studio_fur_homematic