CVE-2013-6951: High severity Belkin WeMo Home Automation firmware vulnerability
Published Feb 22, 2014
·Updated
The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary X.509 certificate.
Affected Software
1 affected component
Belkin WeMo Home Automation firmware=2769
Event History
Feb 22, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6951?
CVE-2013-6951 has a high severity rating due to its potential to enable man-in-the-middle attacks.
2
How do I fix CVE-2013-6951?
To fix CVE-2013-6951, users should update the Belkin WeMo Home Automation firmware to version 3949 or later.
3
What type of attacks does CVE-2013-6951 allow?
CVE-2013-6951 allows man-in-the-middle attackers to spoof SSL servers using arbitrary X.509 certificates.
4
Which devices are affected by CVE-2013-6951?
CVE-2013-6951 affects Belkin WeMo Home Automation firmware versions prior to 3949.
5
Is CVE-2013-6951 exploited in the wild?
While it is possible for CVE-2013-6951 to be exploited, there have been no significant reports of active exploitation.