CVE-2018-15476
Summary
| CVE | CVE-2018-15476 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-30 17:29:00 UTC |
| Updated | 2018-11-09 15:51:00 UTC |
| Description | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by the device. As a result, an attacker in control of the network traffic of a device could have taken control of a device by intercepting and modifying commands issued from the server to the device in a Man-in-the-Middle attack. This included the ability to inject firmware update commands into the communication and cause the device to install maliciously modified firmware. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Mystrom | Wifi Bulb | - | All | All | All |
| Hardware | Mystrom | Wifi Bulb | - | All | All | All |
| Operating System | Mystrom | Wifi Bulb Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Bulb Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Button | - | All | All | All |
| Hardware | Mystrom | Wifi Button | - | All | All | All |
| Operating System | Mystrom | Wifi Button Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Button Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Button Plus | - | All | All | All |
| Hardware | Mystrom | Wifi Button Plus | - | All | All | All |
| Operating System | Mystrom | Wifi Button Plus Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Button Plus Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Led Strip | - | All | All | All |
| Hardware | Mystrom | Wifi Led Strip | - | All | All | All |
| Operating System | Mystrom | Wifi Led Strip Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Led Strip Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Switch | v1 | All | All | All |
| Hardware | Mystrom | Wifi Switch | v2 | All | All | All |
| Hardware | Mystrom | Wifi Switch | v1 | All | All | All |
| Hardware | Mystrom | Wifi Switch | v2 | All | All | All |
| Hardware | Mystrom | Wifi Switch Eu | - | All | All | All |
| Hardware | Mystrom | Wifi Switch Eu | - | All | All | All |
| Operating System | Mystrom | Wifi Switch Eu Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Switch Eu Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Switch Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Switch Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-schweiz... | MISC | www.swisscom.ch | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.