CVE-2015-6033: Critical severity qolsys iq panel vulnerability
Published Oct 31, 2015
·Updated
Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass intended access restrictions via a modified update.
Affected Software
1 affected component
Qolsys Iq Panel Android<=1.5.0
Event History
Oct 31, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6033?
CVE-2015-6033 has a moderate severity rating due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2015-6033?
To fix CVE-2015-6033, update the Qolsys IQ Panel to version 1.5.1 or later.
3
What type of attack does CVE-2015-6033 allow?
CVE-2015-6033 allows man-in-the-middle attackers to bypass access restrictions.
4
Which versions of Qolsys IQ Panel are affected by CVE-2015-6033?
CVE-2015-6033 affects Qolsys IQ Panel versions before 1.5.1.
5
What issue exists in Qolsys IQ Panel related to CVE-2015-6033?
The issue in CVE-2015-6033 is that the Qolsys IQ Panel does not verify digital signatures of software updates.