PT-2018-13172 · Logitech · Logitech Harmony Hub
Publicado
2018-12-20
·
Atualizado
2019-10-09
·
CVE-2018-15722
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Logitech Harmony Hub versions prior to 4.15.206
Description
The issue allows for OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.
Recommendations
For versions prior to 4.15.206, update to version 4.15.206 or later to resolve the issue. As a temporary workaround, consider restricting access to the time update request to minimize the risk of exploitation.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Logitech Harmony Hub