7.5
CVSSv3

CVE-2021-20992

Published: 19/04/2021 Updated: 23/04/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fibaro home_center_2_firmware

fibaro home_center_lite_firmware

Exploits

Fibaro Home Center Light and Fibaro Home Center 2 versions 4600 and below suffer from man-in-the-middle, missing authentication, remote command execution, and missing encryption vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [CVE-2021-20989, CVE-2021-20990, CVE-2021-20991, CVE-2021-20992] Multiple vulnerabilities in Fibaro Home Center <!--X- ...