Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-6952

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2013-6952
Last Modified 05 Mar 2014 11:49:56
Published 22 Feb 2014 04:55:09
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2013-6952

Summary

The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware updates and execute arbitrary code via crafted signed data.

Vulnerable Systems

Application

  • Belkin Wemo Home Automation Firmware 2769


References

CERT-VN - VU#656302

MISC - http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf


Last Updated: 27 May 2016 11:04:31