1 results (0.003 seconds)

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 2

Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to use an unauthenticated cloud service for an indeterminate time period (possibly forever). Once an individual device's firmware is updated, and authentication occurs once, the cloud service recategorizes the device so that authentication is subsequently always required, and spoofing cannot occur. Los dispositivos Loxone Miniserver con versiones de firmware anteriores a 11.1 (también se conoce como versión 11.1.9.3) no pueden utilizar un método de autenticación que se base en la "signature of the update package". Por lo tanto, estos dispositivos (o atacantes que falsifican estos dispositivos) pueden continuar usando un servicio en la nube no autenticado durante un período de tiempo indeterminado (posiblemente para siempre). • https://iot-lab-fh-ooe.github.io/loxone_clouddns_schwachstelle https://iot-lab-fh-ooe.github.io/loxone_clouddns_vulnerability https://www.loxone.com/dede/sicherheit-cloud-dns https://www.loxone.com/enen/security-cloud-dns • CWE-287: Improper Authentication •