CVE-2018-15723
Summary
| CVE | CVE-2018-15723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-20 21:29:00 UTC |
| Updated | 2019-10-09 23:35:00 UTC |
| Description | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Logitech | Harmony Hub | - | All | All | All |
| Hardware | Logitech | Harmony Hub | - | All | All | All |
| Operating System | Logitech | Harmony Hub Firmware | All | All | All | All |
| Operating System | Logitech | Harmony Hub Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [R1] Logitech Harmony Hub Multiple Vulnerabilities - Research Advisory | Tenable® | MISC | www.tenable.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.