CVE-2018-6402
7.5
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD
Description
Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if the device settings specify use of encryption such as WPA2, as long as the competing network has a stronger signal. An attacker must be able to set up a nearby SSID, similar to an "Evil Twin" attack.
Affected (1)
Products: Ecobee: Ecobee4 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.2.0.171 |
| Running on/with | Platform Versions |
|---|---|
Ecobee Ecobee4 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.