CVE-2021-20992
19.04.2021, 14:15
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.Enginsight
Vendor | Product | Version |
---|---|---|
fibaro | home_center_2_firmware | * |
fibaro | home_center_lite_firmware | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References