PT-2020-12495 · Thinx · Thinx-Device-Api
Suculent
·
Published
2020-04-30
·
Updated
2022-10-29
·
CVE-2020-11015
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
thinx-device-api IoT Device Management Server versions prior to 2.5.0
Description
A vulnerability has been disclosed in the thinx-device-api IoT Device Management Server, where the device MAC address can be spoofed. This allows initial registration requests without a UDID and a spoofed MAC address to create a new UDID with the same MAC address. The full impact of this issue needs to be reviewed further. It applies to all users, mostly those using ESP8266/ESP32 devices.
Recommendations
For versions prior to 2.5.0, update to firmware version 2.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the initial registration request endpoint to minimize the risk of exploitation. Avoid using spoofed MAC addresses in registration requests until the issue is resolved.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thinx-Device-Api