Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-6951

Overview

Vulnerability Score 7.1 7.1
CVE Id CVE-2013-6951
Last Modified 24 Feb 2014 12:19:56
Published 22 Feb 2014 04:55:09
Confidentiality Impact NONE NONE
Integrity Impact COMPLETE COMPLETE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2013-6951

Summary

The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary X.509 certificate.

Vulnerable Systems

Application

  • Belkin Wemo Home Automation Firmware 2769


References

CERT-VN - VU#656302

MISC - http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf


Last Updated: 27 May 2016 11:03:22