PT-2014-1986 · Vivint · Vivint Sky Control Panel

Publicado

2014-09-25

·

Atualizado

2017-01-25

·

CVE-2014-8362

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vivint Sky Control Panel version 1.1.1.9926
Description The issue is related to the lack of authentication for critical functions in the Vivint Sky Control Panel web application. This allows a remote attacker to enable and disable the alarm system and modify other security settings via the web-enabled interface, which by default listens on port 8090.
Recommendations For Vivint Sky Control Panel version 1.1.1.9926, consider restricting access to the web interface, particularly to port 8090, until a fix is available. As a temporary workaround, limit remote access to the control panel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02425
CVE-2014-8362

Produtos afetados

Vivint Sky Control Panel