PT-2018-12883 · Zipato · Zipato Zipabox Smart Home Controller

Andrey Muravitsky

·

Published

2018-08-13

·

Updated

2019-10-03

·

CVE-2018-15123

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118
Description The issue concerns insecure configuration storage, allowing a remote attacker to perform new attack vectors and gain control over the device and smart home.
Recommendations For Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118, consider restricting access to the device until a secure configuration storage solution is implemented. As a temporary workaround, limit the exposure of the device to the internet and isolate it from the smart home network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-15123

Affected Products

Zipato Zipabox Smart Home Controller