PT-2017-8675 · Osram Sylvania · Osram Lightify Home
Deral Heiland
·
Published
2017-04-10
·
Updated
2017-04-14
·
CVE-2016-5053
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OSRAM SYLVANIA Osram Lightify Home versions prior to 2016-07-26
Description
The issue allows remote attackers to execute arbitrary commands. This can be done via TCP port 4000.
Recommendations
For OSRAM SYLVANIA Osram Lightify Home versions prior to 2016-07-26, update to a version released after 2016-07-26 to resolve the issue. As a temporary workaround, consider restricting access to TCP port 4000 to minimize the risk of exploitation.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Osram Lightify Home