PT-2021-11397 · Loxone · Loxone Miniserver

Di Markus Zeilinger

+2

·

Published

2021-01-13

·

Updated

2021-01-21

·

CVE-2020-27488

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Loxone Miniserver versions prior to 11.1
Description: The issue affects devices that cannot use an authentication method based on the signature of the update package. As a result, these devices, or attackers spoofing them, can continue to use an unauthenticated cloud service indefinitely. Once a device's firmware is updated and authentication occurs, the cloud service requires authentication for subsequent interactions, preventing spoofing.
Recommendations: For versions prior to 11.1, update the firmware to version 11.1 or later to enable authentication based on the signature of the update package and prevent unauthorized access to the cloud service.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27488

Affected Products

Loxone Miniserver