PT-2018-12883 · Zipato · Zipato Zipabox Smart Home Controller
Andrey Muravitsky
·
Published
2018-08-13
·
Updated
2019-10-03
·
CVE-2018-15123
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118
Description
The issue concerns insecure configuration storage, allowing a remote attacker to perform new attack vectors and gain control over the device and smart home.
Recommendations
For Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118, consider restricting access to the device until a secure configuration storage solution is implemented. As a temporary workaround, limit the exposure of the device to the internet and isolate it from the smart home network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zipato Zipabox Smart Home Controller