PT-2023-2623 · Nexx · Nexx Garage Door Controller+3

CVE-2023-1752

·

Publicado

2023-04-04

·

Atualizado

2023-04-12

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nexx Smart Home devices (affected versions not specified) Nexx Garage Door Controller (NXG-100B, NXG-200) Nexx Smart Plug (NXPG-100W) Nexx Smart Alarm (NXAL-100)
Description The issue is related to weaknesses in the authentication procedure of Nexx Smart Home devices. This could allow any user to register an already registered alarm or associated device with only the device’s MAC address.
Recommendations For Nexx Smart Home devices, consider restricting access to device registration until a patch is available. For Nexx Garage Door Controller, Nexx Smart Plug, and Nexx Smart Alarm, avoid using the device registration feature with only the device’s MAC address until the issue is resolved. As a temporary workaround, consider disabling device registration for already registered alarms or associated devices until a patch is available.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02463
CVE-2023-1752

Produtos afetados

Nexx Garage Door Controller
Nexx Smart Alarm
Nexx Smart Home
Nexx Smart Plug