CVE-2023-50127
Last modified
CVE-2023-50127 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from any given phone number.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from any given phone number.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hozard | Alarm System | 1.0 |
References
- https://www.secura.com/services/iot/consumer-products/security-concerns-in-popular-smart-home-devicesExploit, Third Party Advisory
- https://www.secura.com/services/iot/consumer-products/security-concerns-in-popular-smart-home-devicesExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-50127?
How severe is CVE-2023-50127?
How do I fix CVE-2023-50127?
Are you affected by CVE-2023-50127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
