PT-2014-4649 · Oleumtech · Oleumtech Wio Dh2 Wireless Gateway+2
Publicado
2014-07-24
·
Atualizado
2025-10-06
·
CVE-2014-2361
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules
Description
The issue allows physically proximate attackers to spoof communication by obtaining the site security key after using direct hardware access or manual-setup mode, as no authentication is required for reading this key when BreeZ is used.
Recommendations
For OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, consider implementing authentication for reading the site security key when BreeZ is used to prevent unauthorized access. As a temporary workaround, restrict physical access to the devices to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Breez
Oleumtech Wio Dh2 Wireless Gateway
Sensor Wireless I/O Modules