An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by the device. As a result, an attacker in control of the network traffic of a device could have taken control of a device by intercepting and modifying commands issued from the server to the device in a Man-in-the-Middle attack. This included the ability to inject firmware update commands into the communication and cause the device to install maliciously modified firmware.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Mystrom
Subscribe
|
Wifi Bulb
Subscribe
Wifi Bulb Firmware
Subscribe
Wifi Button
Subscribe
Wifi Button Firmware
Subscribe
Wifi Button Plus
Subscribe
Wifi Button Plus Firmware
Subscribe
Wifi Led Strip
Subscribe
Wifi Led Strip Firmware
Subscribe
Wifi Switch
Subscribe
Wifi Switch Eu
Subscribe
Wifi Switch Eu Firmware
Subscribe
Wifi Switch Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7354 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by the device. As a result, an attacker in control of the network traffic of a device could have taken control of a device by intercepting and modifying commands issued from the server to the device in a Man-in-the-Middle attack. This included the ability to inject firmware update commands into the communication and cause the device to install maliciously modified firmware. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:54:03.502Z
Reserved: 2018-08-17T00:00:00.000Z
Link: CVE-2018-15476
No data.
Status : Modified
Published: 2018-08-30T17:29:01.143
Modified: 2024-11-21T03:50:53.547
Link: CVE-2018-15476
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD