Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-6950

Overview

Vulnerability Score 7.8 7.8
CVE Id CVE-2013-6950
Last Modified 05 Mar 2014 11:49:56
Published 22 Feb 2014 04:55:09
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2013-6950

Summary

The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the-middle attackers to install arbitrary firmware by spoofing a distribution server.

Vulnerable Systems

Application

  • Belkin Wemo Home Automation Firmware 2769


References

CERT-VN - VU#656302

MISC - http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf


Last Updated: 27 May 2016 11:04:31