VYPR
Vendor

Ismartalarm

Sign in to watch
Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-13664Cri0.649.80.01Dec 1, 2017Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.
CVE-2017-7728Cri0.649.80.02Jul 11, 2017On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
CVE-2017-7730Hig0.497.50.00Jul 11, 2017iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.
CVE-2017-7729Hig0.497.50.00Jul 11, 2017On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
CVE-2017-7726Hig0.497.50.00Jul 11, 2017iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.