CVE-2013-6950: High severity Belkin WeMo Home Automation firmware vulnerability
The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the-middle attackers to install arbitrary firmware by spoofing a distribution server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Belkin WeMo Home Automation firmwareto a version that resolves this vulnerability.Fixed in 3949 - Compensating control
Use a trusted distribution feed/server (or otherwise prevent distribution-feed spoofing) so clients cannot be tricked into installing arbitrary firmware.
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6950?
CVE-2013-6950 is classified as a medium severity vulnerability due to its potential for exploitation by man-in-the-middle attackers.
How do I fix CVE-2013-6950?
To fix CVE-2013-6950, update the Belkin WeMo Home Automation firmware to version 3949 or later.
What systems are affected by CVE-2013-6950?
CVE-2013-6950 affects Belkin WeMo Home Automation firmware versions before 3949.
What type of attack does CVE-2013-6950 allow?
CVE-2013-6950 allows man-in-the-middle attackers to install arbitrary firmware by spoofing a distribution server.
Is there a workaround for CVE-2013-6950?
There is no official workaround for CVE-2013-6950 other than upgrading the firmware.