Vulnerability Description
Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device initiated remote port-forward channel can be used to connect to the web management interface. Knowledge of authorization credentials to the management interface is required to perform any further actions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fibaro | Home Center 2 Firmware | <= 4.600 |
| Fibaro | Home Center 2 | - |
| Fibaro | Home Center Lite Firmware | <= 4.600 |
| Fibaro | Home Center Lite | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162243/Fibaro-Home-Center-MITM-Missing-AuthExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/27Mailing ListThird Party Advisory
- https://www.iot-inspector.com/blog/advisory-fibaro-home-center/ExploitThird Party Advisory
- http://packetstormsecurity.com/files/162243/Fibaro-Home-Center-MITM-Missing-AuthExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/27Mailing ListThird Party Advisory
- https://www.iot-inspector.com/blog/advisory-fibaro-home-center/ExploitThird Party Advisory
FAQ
What is CVE-2021-20989?
CVE-2021-20989 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can b...
How severe is CVE-2021-20989?
CVE-2021-20989 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20989?
Check the references section above for vendor advisories and patch information. Affected products include: Fibaro Home Center 2 Firmware, Fibaro Home Center 2, Fibaro Home Center Lite Firmware, Fibaro Home Center Lite.