PT-2020-8980 · Philips · Philips Hue

Ilia Shnaidman

·

Published

2020-12-21

·

Updated

2022-08-06

·

CVE-2018-7580

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Philips Hue (affected versions not specified)
Description The issue is related to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub, causing it to stop responding. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2018-7580

Affected Products

Philips Hue