PT-2024-13387 · Meross · Meross Msh30Q

Adam Lindberg

·

Published

2024-01-23

·

Updated

2024-01-29

·

CVE-2023-46892

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Meross MSH30Q version 4.5.23
Description The radio frequency communication protocol used by the device is susceptible to replay attacks. This allows attackers to record and replay previously captured communication, enabling them to execute unauthorized commands or actions, such as modifying the thermostat's temperature.
Recommendations For Meross MSH30Q version 4.5.23, consider implementing authentication mechanisms to verify the authenticity of incoming commands to prevent replay attacks. As a temporary workaround, restrict access to the device's communication protocol to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-46892

Affected Products

Meross Msh30Q