CVE-2017-17691
Summary
| CVE | CVE-2017-17691 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-07 22:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Contronics | Homeputer Cl Studio Fur Homematic | All | All | All | All |
| Application | Contronics | Homeputer Cl Studio Fur Homematic | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-031_homematic.txt | MISC | www.compass-security.com | Exploit, Mitigation, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.