CVE-2018-15720: Critical severity logitech harmony hub vulnerability
Published Dec 20, 2018
·Updated
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.
Affected Software
2 affected components
Logitech Harmony Hub Firmware<4.15.206
Logitech Harmony Hub
Event History
Dec 20, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-15720?
CVE-2018-15720 is classified as high severity due to the presence of hard-coded accounts that allow remote unauthorized access.
2
How do I fix CVE-2018-15720?
To fix CVE-2018-15720, upgrade your Logitech Harmony Hub firmware to version 4.15.206 or later.
3
What impact does CVE-2018-15720 have on my Logitech Harmony Hub?
CVE-2018-15720 allows attackers to access the local API and control devices connected to the Harmony Hub remotely.
4
Is my Logitech Harmony Hub affected by CVE-2018-15720?
If your Logitech Harmony Hub is running a firmware version prior to 4.15.206, it is vulnerable to CVE-2018-15720.
5
What are the default accounts exposed by CVE-2018-15720?
CVE-2018-15720 includes two hard-coded accounts in the XMPP server of the Harmony Hub, which should not be accessible.