Lucene search

K
cveRapid7CVE-2023-5881
HistoryJan 03, 2024 - 8:15 p.m.

CVE-2023-5881

2024-01-0320:15:21
CWE-306
rapid7
web.nvd.nist.gov
23
genie
aladdin connect
cve-2023-5881
garage door
security
access control

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

37.2%

Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) “Garage Door Control Module Setup” and modify the Garage door’s SSID settings.

Affected configurations

Nvd
Node
geniecompanyaladdin_connect_garage_door_opener_firmwareRange14.1.1
AND
geniecompanyaladdin_connect_garage_door_openerMatch-
VendorProductVersionCPE
geniecompanyaladdin_connect_garage_door_opener_firmware*cpe:2.3:o:geniecompany:aladdin_connect_garage_door_opener_firmware:*:*:*:*:*:*:*:*
geniecompanyaladdin_connect_garage_door_opener-cpe:2.3:h:geniecompany:aladdin_connect_garage_door_opener:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "RTOS"
    ],
    "product": "Aladdin Connect (Retrofit-Kit)",
    "vendor": "The Genie Company",
    "versions": [
      {
        "lessThanOrEqual": "<=14.1.1",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

37.2%