Fibaro Home Center Unencrypted management interface
Vulnerability Description
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-20992
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Marton Illes IoT Inspector Research Lab https://www.iot-inspector.com
References
More from Fibar Group S.A
View All →Affected Vendor
Fibar Group S.A
View all reports →