7.5
CVE-2023-1751
- EPSS 0.31%
- Veröffentlicht 04.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:39:49
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Getnexx ≫ Nxal-100 Firmware Version <= nxal100v-p1-9-1
Getnexx ≫ Nxg-100b Firmware Version <= nxg100bv-p3-4-1
Getnexx ≫ Nxpg-100w Firmware Version <= nxpg100cv4-0-0
Getnexx ≫ Nxg-200 Firmware Version <= nxg200v-p3-4-1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.536 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| ics-cert@hq.dhs.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|