PT-2024-13866 · Unknown · Hozard Alarm System

Published

2024-01-11

·

Updated

2024-01-18

·

CVE-2023-50127

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hozard alarm system (Alarmsysteem) version 1.0
Description The issue concerns Improper Authentication in the Hozard alarm system. Specifically, commands sent via the SMS functionality are accepted from random phone numbers. This allows an attacker to disarm the alarm system from any given phone number.
Recommendations For Hozard alarm system (Alarmsysteem) version 1.0, consider restricting access to the SMS functionality to trusted phone numbers as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-50127

Affected Products

Hozard Alarm System