PT-2014-1986 · Vivint · Vivint Sky Control Panel
Publicado
2014-09-25
·
Atualizado
2017-01-25
·
CVE-2014-8362
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vivint Sky Control Panel version 1.1.1.9926
Description
The issue is related to the lack of authentication for critical functions in the Vivint Sky Control Panel web application. This allows a remote attacker to enable and disable the alarm system and modify other security settings via the web-enabled interface, which by default listens on port 8090.
Recommendations
For Vivint Sky Control Panel version 1.1.1.9926, consider restricting access to the web interface, particularly to port 8090, until a fix is available. As a temporary workaround, limit remote access to the control panel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vivint Sky Control Panel