PT-2021-11397 · Loxone · Loxone Miniserver
Di Markus Zeilinger
+2
·
Published
2021-01-13
·
Updated
2021-01-21
·
CVE-2020-27488
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Loxone Miniserver versions prior to 11.1
Description:
The issue affects devices that cannot use an authentication method based on the
signature of the update package. As a result, these devices, or attackers spoofing them, can continue to use an unauthenticated cloud service indefinitely. Once a device's firmware is updated and authentication occurs, the cloud service requires authentication for subsequent interactions, preventing spoofing.Recommendations:
For versions prior to 11.1, update the firmware to version 11.1 or later to enable authentication based on the
signature of the update package and prevent unauthorized access to the cloud service.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loxone Miniserver