PT-2014-1986 · Vivint · Vivint Sky Control Panel
Published
2014-09-25
·
Updated
2017-01-25
·
CVE-2014-8362
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vivint Sky Control Panel version 1.1.1.9926
Description
The issue is related to the lack of authentication for critical functions in the Vivint Sky Control Panel web application. This allows a remote attacker to enable and disable the alarm system and modify other security settings via the web-enabled interface, which by default listens on port 8090.
Recommendations
For Vivint Sky Control Panel version 1.1.1.9926, consider restricting access to the web interface, particularly to port 8090, until a fix is available. As a temporary workaround, limit remote access to the control panel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vivint Sky Control Panel