CVE-2023-50127

Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from any given phone number.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hozard:alarm_system:1.0:*:*:*:*:*:*:*

History

18 Jan 2024, 20:21

Type Values Removed Values Added
References () https://www.secura.com/services/iot/consumer-products/security-concerns-in-popular-smart-home-devices - () https://www.secura.com/services/iot/consumer-products/security-concerns-in-popular-smart-home-devices - Exploit, Third Party Advisory
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CPE cpe:2.3:a:hozard:alarm_system:1.0:*:*:*:*:*:*:*
First Time Hozard
Hozard alarm System

12 Jan 2024, 13:47

Type Values Removed Values Added
Summary
  • (es) El sistema de alarma Hozard (Alarmsysteem) v1.0 es vulnerable a una autenticación incorrecta. Los comandos enviados a través de la funcionalidad SMS se aceptan desde números de teléfono aleatorios, lo que permite a un atacante desarmar el sistema de alarma desde cualquier número de teléfono determinado.

11 Jan 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-11 21:15

Updated : 2024-01-18 20:21


NVD link : CVE-2023-50127

Mitre link : CVE-2023-50127

CVE.ORG link : CVE-2023-50127


JSON object : View

Products Affected

hozard

  • alarm_system
CWE
CWE-287

Improper Authentication