First published: Sat Feb 22 2014(Updated: )
The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the-middle attackers to install arbitrary firmware by spoofing a distribution server.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Belkin WeMo Home Automation firmware | =2769 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6950 is classified as a medium severity vulnerability due to its potential for exploitation by man-in-the-middle attackers.
To fix CVE-2013-6950, update the Belkin WeMo Home Automation firmware to version 3949 or later.
CVE-2013-6950 affects Belkin WeMo Home Automation firmware versions before 3949.
CVE-2013-6950 allows man-in-the-middle attackers to install arbitrary firmware by spoofing a distribution server.
There is no official workaround for CVE-2013-6950 other than upgrading the firmware.