PT-2024-13387 · Meross · Meross Msh30Q
Adam Lindberg
·
Published
2024-01-23
·
Updated
2024-01-29
·
CVE-2023-46892
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Meross MSH30Q version 4.5.23
Description
The radio frequency communication protocol used by the device is susceptible to replay attacks. This allows attackers to record and replay previously captured communication, enabling them to execute unauthorized commands or actions, such as modifying the thermostat's temperature.
Recommendations
For Meross MSH30Q version 4.5.23, consider implementing authentication mechanisms to verify the authenticity of incoming commands to prevent replay attacks. As a temporary workaround, restrict access to the device's communication protocol to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meross Msh30Q