Lucene search

K
nvd[email protected]NVD:CVE-2013-4860
HistoryJun 05, 2014 - 8:55 p.m.

CVE-2013-4860

2014-06-0520:55:05
CWE-264
web.nvd.nist.gov
3

CVSS2

8.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0.006

Percentile

78.5%

Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.

Affected configurations

Nvd
Node
radiothermostatct50_firmwareRange1.4.64
AND
radiothermostatct50Match-
Node
radiothermostatct80_firmwareRange1.4.64
AND
radiothermostatct80Match-
VendorProductVersionCPE
radiothermostatct50_firmware*cpe:2.3:o:radiothermostat:ct50_firmware:*:*:*:*:*:*:*:*
radiothermostatct50-cpe:2.3:h:radiothermostat:ct50:-:*:*:*:*:*:*:*
radiothermostatct80_firmware*cpe:2.3:o:radiothermostat:ct80_firmware:*:*:*:*:*:*:*:*
radiothermostatct80-cpe:2.3:h:radiothermostat:ct80:-:*:*:*:*:*:*:*

CVSS2

8.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0.006

Percentile

78.5%

Related for NVD:CVE-2013-4860