VYPR
Unrated severityNVD Advisory· Published Oct 25, 2022· Updated Apr 15, 2025

CVE-2022-29475

CVE-2022-29475

Description

An information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A man-in-the-middle vulnerability in the XFINDER service of Abode iota security kits (6.9X/6.9Z) can disclose sensitive information and allow privilege escalation.

Vulnerability

The XFINDER service (UDP/55030) on Abode Systems iota All-In-One Security Kit versions 6.9X and 6.9Z uses a static XOR key for obfuscation, which can be recovered by an attacker. This allows specially crafted man-in-the-middle (MITM) attacks that exploit the weak encryption to reveal sensitive data [1].

Exploitation

An attacker must be positioned on the local network to perform a MITM attack between the iota device and legitimate XFINDER peers or the cloud. The attacker captures XFINDER network traffic, reverses the static XOR obfuscation (key is 64 bytes, used with bitwise NOT and XOR), and replays or modifies packets. No authentication is required, but the attacker must be able to intercept and inject packets on the LAN [1].

Impact

Successful exploitation leads to information disclosure of sensitive data transmitted via XFINDER, which can then be used to escalate privileges on the device. The attacker gains a low-level foothold (CVSS 4.7) with potential to compromise further security controls [1].

Mitigation

As of the advisory publication (October 25, 2022), no patched firmware version has been released by Abode Systems. Users should restrict local network access to the iota device, monitor for unauthorized traffic on UDP/55030, and apply any future updates promptly [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.