Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.
References
Link | Resource |
---|---|
https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-031_homematic.txt | Exploit Mitigation Third Party Advisory |
https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-031_homematic.txt | Exploit Mitigation Third Party Advisory |
Configurations
History
21 Nov 2024, 03:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-031_homematic.txt - Exploit, Mitigation, Third Party Advisory |
Information
Published : 2018-09-07 22:29
Updated : 2024-11-21 03:18
NVD link : CVE-2017-17691
Mitre link : CVE-2017-17691
CVE.ORG link : CVE-2017-17691
JSON object : View
Products Affected
contronics
- homeputer_cl_studio_fur_homematic
CWE
CWE-522
Insufficiently Protected Credentials