PT-2021-10712 · Smartwares · Smartwares Home Easy

Gjoko Krstic

·

Published

2021-04-29

·

Updated

2022-10-05

·

CVE-2020-21997

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Smartwares HOME easy versions prior to 1.0.9
Description The issue allows for an unauthenticated database backup download and information disclosure. This could lead to the disclosure of sensitive and clear-text information, potentially resulting in authentication bypass, session hijacking, and full system control.
Recommendations For versions prior to 1.0.9, update to version 1.0.9 or later to resolve the issue.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-21997

Affected Products

Smartwares Home Easy