CVE-2017-14797
Last modified
CVE-2017-14797 is a vulnerability of currently unknown severity. Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Philips | Hue Bridge Bsb002 Firmware | 1707040932 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14797?
How severe is CVE-2017-14797?
How do I fix CVE-2017-14797?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14791Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-14792Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-14793Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-14794Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-14795The hevc_write_frame function in libbpg.c in libbpg 0.9.7 al…
- CVE-2017-14796The hevc_write_frame function in libbpg.c in libbpg 0.9.7 al…
- CVE-2017-14798A race condition in the postgresql init script could be used…7.3
- CVE-2017-14799A cross site scripting attack in handling the ESP login para…4.6
- CVE-2017-1480IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6,…4.3
- CVE-2017-14800A reflected cross site scripting attack in the NetIQ Access …5.4
- CVE-2017-14801Reflected XSS in the NetIQ Access Manager before 4.3.3 allow…4.6
- CVE-2017-14802Novell Access Manager Admin Console and IDP servers before 4…5.4
Are you affected by CVE-2017-14797?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
