CVE-2023-46892
Last modified
CVE-2023-46892 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication to execute unauthorized commands or actions (e.g., thermostat's temperature).. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication to execute unauthorized commands or actions (e.g., thermostat's temperature).
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Meross | Msh30q Firmware | 4.5.23 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-46892?
How severe is CVE-2023-46892?
How do I fix CVE-2023-46892?
Are you affected by CVE-2023-46892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
