CVE-2024-9991
Cleartext Storage of Sensitive Information Vulnerability in Philips Lighting Devices
Severity Score
7.0
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi credentials stored on the vulnerable device.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the Wi-Fi network to which vulnerable device is connected.
*Credits:
This vulnerability is reported by Shravan Singh, Amey Chavekar. Vishal Giri and Dr. Faruk Kazi from CoE- CNDS Lab, VJTI Mumbai, India
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-10-15 CVE Reserved
- 2024-10-25 CVE Published
- 2024-10-25 CVE Updated
- 2024-10-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-312: Cleartext Storage of Sensitive Information
CAPEC
- CAPEC-37: Retrieve Embedded Sensitive Data
References (1)
URL | Tag | Source |
---|---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0329 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Philips Lighting (Signify Innovations India) Search vendor "Philips Lighting (Signify Innovations India)" | Philips Smart Wi-Fi LED Batten 24-Watt Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart Wi-Fi LED Batten 24-Watt" | < 1.33.1 Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart Wi-Fi LED Batten 24-Watt" and version " < 1.33.1" | en |
Affected
| ||||||
Philips Lighting (Signify Innovations India) Search vendor "Philips Lighting (Signify Innovations India)" | Philips Smart Wi-Fi LED T Beamer 20-Watt Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart Wi-Fi LED T Beamer 20-Watt" | < 1.33.1 Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart Wi-Fi LED T Beamer 20-Watt" and version " < 1.33.1" | en |
Affected
| ||||||
Philips Lighting (Signify Innovations India) Search vendor "Philips Lighting (Signify Innovations India)" | Philips Smart Bulb 9,10,12-Watt Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart Bulb 9,10,12-Watt" | < 1.33.1 Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart Bulb 9,10,12-Watt" and version " < 1.33.1" | en |
Affected
| ||||||
Philips Lighting (Signify Innovations India) Search vendor "Philips Lighting (Signify Innovations India)" | Philips Smart T-Bulb 10,12-Watt Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart T-Bulb 10,12-Watt" | < 1.33.1 Search vendor "Philips Lighting (Signify Innovations India)" for product "Philips Smart T-Bulb 10,12-Watt" and version " < 1.33.1" | en |
Affected
|