HIGH · 7.5

CVE-2021-20990

In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication...

Vulnerability Description

In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdown, a reboot or a reboot into recovery mode.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
FibaroHome Center 2 Firmware<= 4.600
FibaroHome Center 2-
FibaroHome Center Lite Firmware<= 4.600
FibaroHome Center Lite-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-20990?

CVE-2021-20990 is a vulnerability with a CVSS score of 7.5 (HIGH). In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication...

How severe is CVE-2021-20990?

CVE-2021-20990 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-20990?

Check the references section above for vendor advisories and patch information. Affected products include: Fibaro Home Center 2 Firmware, Fibaro Home Center 2, Fibaro Home Center Lite Firmware, Fibaro Home Center Lite.