Vulnerability Description
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nanoleaf | Nanoleaf Firmware | 7.1.1 |
Related Weaknesses (CWE)
References
- http://nanoleaf.comProduct
- https://pwning.tech/cve-2022-47758ExploitTechnical DescriptionThird Party Advisory
- https://pwning.tech/cve-2022-47758/
- http://nanoleaf.comProduct
- https://pwning.tech/cve-2022-47758ExploitTechnical DescriptionThird Party Advisory
- https://pwning.tech/cve-2022-47758/
FAQ
What is CVE-2022-47758?
CVE-2022-47758 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
How severe is CVE-2022-47758?
CVE-2022-47758 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-47758?
Check the references section above for vendor advisories and patch information. Affected products include: Nanoleaf Nanoleaf Firmware.