An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. Devices did not authenticate themselves to the cloud in device to cloud communication. This lack of device authentication allowed an attacker to impersonate any device by guessing or learning their MAC address.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Mystrom
Subscribe
|
Wifi Bulb
Subscribe
Wifi Bulb Firmware
Subscribe
Wifi Button
Subscribe
Wifi Button Firmware
Subscribe
Wifi Button Plus
Subscribe
Wifi Button Plus Firmware
Subscribe
Wifi Led Strip
Subscribe
Wifi Led Strip Firmware
Subscribe
Wifi Switch
Subscribe
Wifi Switch Eu
Subscribe
Wifi Switch Eu Firmware
Subscribe
Wifi Switch Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7357 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. Devices did not authenticate themselves to the cloud in device to cloud communication. This lack of device authentication allowed an attacker to impersonate any device by guessing or learning their MAC address. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:54:03.650Z
Reserved: 2018-08-17T00:00:00.000Z
Link: CVE-2018-15479
No data.
Status : Modified
Published: 2018-08-30T17:29:01.503
Modified: 2024-11-21T03:50:54.050
Link: CVE-2018-15479
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD