Ismartalarm
ismartalarm
8 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ismartalarm 1Cubeone Firmware Nov 21, 2024 Nov 20, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically crafted TCP request to port 12345 and 22306, and access sensitive info...Show more |
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password. |
1Ismartalarm 1Cubeone Firmware May 13, 2026 Dec 1, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file. |
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key. |
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding. |
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext. |
1Ismartalarm 1Cubeone Firmware May 13, 2026 Jul 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography. |
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability. |