PT-2021-14318 · Fibaro · Fibaro Home Center 2+1
Marton Illes
·
Published
2021-04-19
·
Updated
2022-10-29
·
CVE-2021-20989
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older
Description:
The issue concerns Fibaro Home Center 2 and Lite devices that initiate SSH connections to the Fibaro cloud for remote access and support. This connection is vulnerable to interception via a DNS spoofing attack, allowing an attacker to use a device-initiated remote port-forward channel to connect to the web management interface. To perform further actions, knowledge of authorization credentials to the management interface is required.
Recommendations:
For firmware version 4.600 and older, update to a version newer than 4.600 to resolve the issue.
As a temporary workaround, consider restricting access to the web management interface until a patch is available.
Avoid using the device-initiated remote port-forward channel for remote access and support until the issue is resolved.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fibaro Home Center 2
Fibaro Home Center Lite