CVE-2018-15721: Critical severity logitech harmony hub vulnerability
Published Dec 20, 2018
·Updated
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to gain access to the local API.
Affected Software
2 affected components
Logitech Harmony Hub Firmware<4.15.206
Logitech Harmony Hub
Event History
Dec 20, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-15721?
CVE-2018-15721 has been classified as a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2018-15721?
To fix CVE-2018-15721, update the Logitech Harmony Hub firmware to version 4.15.206 or later.
3
What type of vulnerability is CVE-2018-15721?
CVE-2018-15721 is an authentication bypass vulnerability in the XMPP server of the Logitech Harmony Hub.
4
Can CVE-2018-15721 be exploited remotely?
Yes, CVE-2018-15721 can be exploited remotely by attackers using a crafted XMPP request.
5
Which devices are affected by CVE-2018-15721?
CVE-2018-15721 affects Logitech Harmony Hub devices running firmware versions prior to 4.15.206.