CVE-2017-13664
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.
Affected (1)
Products: Ismartalarm: Cubeone Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.2.4.8 |
| Running on/with | Platform Versions |
|---|---|
Ismartalarm Cubeone | All versions |
References (2)
https://poppopretn.com/2017/11/30/public-disclosure-firmware-vulnerabilities-in-ismartalarm-cubeone/
Source: cve@mitre.org
ExploitThird Party Advisory
https://poppopretn.com/2017/11/30/public-disclosure-firmware-vulnerabilities-in-ismartalarm-cubeone/
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.