CVE-2023-1751
Summary
| CVE | CVE-2023-1751 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-04 17:15:00 UTC |
| Updated | 2023-11-07 04:04:00 UTC |
| Description | The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Getnexx | Nxal-100 | - | All | All | All |
| Operating System | Getnexx | Nxal-100 Firmware | All | All | All | All |
| Hardware | Getnexx | Nxg-100b | - | All | All | All |
| Operating System | Getnexx | Nxg-100b Firmware | All | All | All | All |
| Hardware | Getnexx | Nxg-200 | - | All | All | All |
| Operating System | Getnexx | Nxg-200 Firmware | All | All | All | All |
| Hardware | Getnexx | Nxpg-100w | - | All | All | All |
| Operating System | Getnexx | Nxpg-100w Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nexx Smart Home Device | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.