RSS   Vulnerabilities for 'Cubeone firmware'   RSS

2018-11-20
 
CVE-2018-16224

CWE-200
 

 
Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically crafted TCP request to port 12345 and 22306, and access sensitive information from the device.

 
2017-12-01
 
CVE-2017-13664

CWE-200
 

 
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.

 
 
CVE-2017-13663

CWE-312
 

 
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.

 

 >>> Vendor: Ismartalarm 3 Products
Cube one firmware
Cubeone firmware
Ismartalarm


Copyright 2024, cxsecurity.com

 

Back to Top