Vulnerability Description
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ismartalarm | Cubeone Firmware | - |
| Ismartalarm | Cubeone | - |
References
- http://dojo.bullguard.com/blog/burglar-hacker-when-a-physical-security-is-comproExploitThird Party Advisory
- http://dojo.bullguard.com/blog/burglar-hacker-when-a-physical-security-is-comproExploitThird Party Advisory
FAQ
What is CVE-2017-7728?
CVE-2017-7728 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
How severe is CVE-2017-7728?
CVE-2017-7728 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-7728?
Check the references section above for vendor advisories and patch information. Affected products include: Ismartalarm Cubeone Firmware, Ismartalarm Cubeone.