Vulnerability Description
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecobee | Ecobee3 Lite Firmware | 4.5.81.200 |
| Ecobee | Ecobee3 Lite | - |
Related Weaknesses (CWE)
References
- https://www.l9group.com/advisories/remote-denial-of-service-of-ecobee3-liteExploitThird Party Advisory
- https://www.l9group.com/advisories/remote-denial-of-service-of-ecobee3-liteExploitThird Party Advisory
FAQ
What is CVE-2021-27953?
CVE-2021-27953 is a vulnerability with a CVSS score of 7.5 (HIGH). A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a den...
How severe is CVE-2021-27953?
CVE-2021-27953 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27953?
Check the references section above for vendor advisories and patch information. Affected products include: Ecobee Ecobee3 Lite Firmware, Ecobee Ecobee3 Lite.