CVE-2021-20992: Fibaro Home Center Unencrypted management interface
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20992?
CVE-2021-20992 is a vulnerability found in Fibaro Home Center 2 and Lite devices that provides a web-based management interface over unencrypted HTTP protocol.
What is the severity of CVE-2021-20992?
The severity of CVE-2021-20992 is high, with a severity value of 7.5.
How can the vulnerability in Fibaro Home Center 2 and Lite devices be exploited?
The vulnerability allows for eavesdropping on communication between the user and the device, potentially leading to the hijacking of sessions, tokens, and passwords.
Which versions of Fibaro Home Center 2 and Lite devices are affected?
All versions of Fibaro Home Center 2 and Lite devices are affected.
Is there a fix available for CVE-2021-20992?
At the moment, there is no information about a specific fix for CVE-2021-20992. It is recommended to follow the vendor's security advisories for updates.