CVE-2017-14797: Weak Encryption
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14797?
CVE-2017-14797 is classified as a high severity vulnerability due to its potential impact on the security of connected accessories.
How do I fix CVE-2017-14797?
To mitigate CVE-2017-14797, ensure that the Philips Hue Bridge is updated to a version that implements transport encryption.
What does CVE-2017-14797 affect?
CVE-2017-14797 affects the Philips Hue Bridge BSB002 with firmware version 1707040932 specifically.
What are the potential consequences of exploiting CVE-2017-14797?
Exploitation of CVE-2017-14797 allows remote attackers to read API keys, bypass pushlink protection, and gain control over connected accessories.
Is the Philips Hue Bridge BSB002 vulnerable to CVE-2017-14797?
Yes, the Philips Hue Bridge BSB002 with firmware version 1707040932 is vulnerable to CVE-2017-14797.