VYPR

Ecobee3 Lite Firmware

by Ecobee

CVEs (3)

  • CVE-2021-27952CriAug 3, 2021
    risk 0.64cvss 9.8epss 0.01

    Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console.

  • CVE-2021-27954HigAug 3, 2021
    risk 0.53cvss 8.2epss 0.01

    A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to force the device to connect to a SSID or cause a denial…

  • CVE-2021-27953HigAug 3, 2021
    risk 0.49cvss 7.5epss 0.02

    A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request.