← volver
CVE-2020-11015

Device Authentication Vulnerability in thinx-device-api IoT Device Management Server

CVSS 7.5 HIGHEPSS 0.7%CWE-290
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.5EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
29 sep 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address may pass to create new UDID with same MAC address. Full impact needs to be reviewed further. Applies to all (mostly ESP8266/ESP32) users. This has been fixed in firmware version 2.5.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Productos afectados
suculent · thinx-device-api

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →