PT-2020-19482 · Evoko · Evoko Home

Published

2020-01-19

·

Updated

2022-05-03

·

CVE-2020-7232

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Evoko Home devices versions 1.31 through 1.37
Description The issue allows remote attackers to obtain sensitive information, such as usernames and password hashes, via a WebSocket request. This can be demonstrated by accessing the sockjs/224/uf1psgff/websocket URI at a wss:// URL.
Recommendations For Evoko Home devices versions 1.31 through 1.37, as a temporary workaround, consider restricting access to the WebSocket endpoint until a patch is available. Avoid using the sensitive information via the WebSocket request until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-7232

Affected Products

Evoko Home