The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:36:44.458Z

Reserved: 2023-03-30T20:04:29.870Z

Link: CVE-2023-1751

cve-icon Vulnrichment

Updated: 2024-08-02T05:57:25.083Z

cve-icon NVD

Status : Modified

Published: 2023-04-04T17:15:07.227

Modified: 2024-11-21T07:39:49.713

Link: CVE-2023-1751

cve-icon Redhat

No data.