First published: Sat Sep 30 2017(Updated: )
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Hue Bridge v2 firmware | =1707040932 | |
Philips Hue Bridge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14797 is classified as a high severity vulnerability due to its potential impact on the security of connected accessories.
To mitigate CVE-2017-14797, ensure that the Philips Hue Bridge is updated to a version that implements transport encryption.
CVE-2017-14797 affects the Philips Hue Bridge BSB002 with firmware version 1707040932 specifically.
Exploitation of CVE-2017-14797 allows remote attackers to read API keys, bypass pushlink protection, and gain control over connected accessories.
Yes, the Philips Hue Bridge BSB002 with firmware version 1707040932 is vulnerable to CVE-2017-14797.