CVE-2018-15722: OS Command Injection
Published Dec 20, 2018
·Updated
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.
Affected Software
2 affected components
Logitech Harmony Hub Firmware<4.15.206
Logitech Harmony Hub
Event History
Dec 20, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-15722?
CVE-2018-15722 has a medium severity level, as it allows OS command injection on affected devices.
2
How do I fix CVE-2018-15722?
To fix CVE-2018-15722, update the Logitech Harmony Hub firmware to version 4.15.206 or higher.
3
What devices are affected by CVE-2018-15722?
CVE-2018-15722 affects Logitech Harmony Hub firmware versions before 4.15.206.
4
What kind of attack does CVE-2018-15722 allow?
CVE-2018-15722 allows remote OS command injection via manipulated time update requests.
5
Can CVE-2018-15722 be exploited remotely?
Yes, CVE-2018-15722 can be exploited remotely by a malicious server or through a man-in-the-middle attack.