PT-2021-14318 · Fibaro · Fibaro Home Center 2+1

·

CVE-2021-20989

·

Published

2021-04-19

·

Updated

2022-10-29

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older
Description: The issue concerns Fibaro Home Center 2 and Lite devices that initiate SSH connections to the Fibaro cloud for remote access and support. This connection is vulnerable to interception via a DNS spoofing attack, allowing an attacker to use a device-initiated remote port-forward channel to connect to the web management interface. To perform further actions, knowledge of authorization credentials to the management interface is required.
Recommendations: For firmware version 4.600 and older, update to a version newer than 4.600 to resolve the issue. As a temporary workaround, consider restricting access to the web management interface until a patch is available. Avoid using the device-initiated remote port-forward channel for remote access and support until the issue is resolved.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20989

Affected Products

Fibaro Home Center 2
Fibaro Home Center Lite