Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device.
References
Link | Resource |
---|---|
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/08/08/klcert-18-004-zipato-zipabox-weak-hash-algorithm/ | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-08-13 14:48
Updated : 2018-10-10 08:35
NVD link : CVE-2018-15124
Mitre link : CVE-2018-15124
JSON object : View
CWE
CWE-326
Inadequate Encryption Strength
Products Affected
zipato
- zipabox
- zipabox_firmware