CVE-2017-18868

Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is built.
References
Link Resource
https://www.hindawi.com/journals/scn/2017/1723658/ Technical Description Third Party Advisory
https://www.hindawi.com/journals/scn/2017/1723658/ Technical Description Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:digi:xbee_2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:digi:xbee_2:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:21

Type Values Removed Values Added
References () https://www.hindawi.com/journals/scn/2017/1723658/ - Technical Description, Third Party Advisory () https://www.hindawi.com/journals/scn/2017/1723658/ - Technical Description, Third Party Advisory

Information

Published : 2020-05-21 20:15

Updated : 2024-11-21 03:21


NVD link : CVE-2017-18868

Mitre link : CVE-2017-18868

CVE.ORG link : CVE-2017-18868


JSON object : View

Products Affected

digi

  • xbee_2_firmware
  • xbee_2
CWE
CWE-276

Incorrect Default Permissions