PT-2014-1986 · Vivint · Vivint Sky Control Panel

Published

2014-09-25

·

Updated

2017-01-25

·

CVE-2014-8362

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vivint Sky Control Panel version 1.1.1.9926
Description The issue is related to the lack of authentication for critical functions in the Vivint Sky Control Panel web application. This allows a remote attacker to enable and disable the alarm system and modify other security settings via the web-enabled interface, which by default listens on port 8090.
Recommendations For Vivint Sky Control Panel version 1.1.1.9926, consider restricting access to the web interface, particularly to port 8090, until a fix is available. As a temporary workaround, limit remote access to the control panel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02425
CVE-2014-8362

Affected Products

Vivint Sky Control Panel