Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.805298
Category:Web application abuses
Title:Loxone Smart Home Multiple Vulnerabilities (Mar 2015)
Summary:Loxone Smart Home is prone to multiple vulnerabilities.
Description:Summary:
Loxone Smart Home is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- the device transmitting all data in cleartext.

- HTTP requests do not require multiple steps, explicit confirmation, or a
unique token when performing certain sensitive actions.

- the '/dev/cfg/version' script does not validate input appended to the
response header before returning it to the user.

- the '/dev/sps/io/' script does not validate input passed via the URL before
returning it to users.

- the '/dev/sps/addcmd/' script does not validate input to the description field
in a new task before returning it to users.

- the program storing user credentials in an insecure manner.

- improper restriction of JavaScript from one web page from accessing another
when the pages originate from different domains.

- an unspecified error related to malformed HTTP requests or using the
synflood metasploit module.

Vulnerability Impact:
Successful exploitation will allow
remote attackers to:

- conduct a man-in-the-middle attack.

- conduct a cross-site request forgery attack.

- conduct a cross-frame scripting (XFS) attack.

- conduct a denial-of-service (DoS) attack.

- decrypt user credentials.

- insert additional arbitrary HTTP headers.

- execute arbitrary script code in a user's browser session within the trust
relationship between their browser and the server.

Affected Software/OS:
Loxone Smart Home version 5.49 and probably prior.

Solution:
Upgrade to Loxone Smart Home version 6.3 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.