ismartalarm
ICS / OT / IoTcommercial
Top products
Latest CVEs
The 8 most recently published vulnerabilities affecting ismartalarm.
- CVE-2018-16222Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.6.8
- CVE-2018-16224Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically crafted TCP request to port 12345 and 22306, an...5.3
- CVE-2017-13664Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from th...9.8
- CVE-2017-13663Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.7.5
- CVE-2017-7728On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.9.8
- CVE-2017-7726iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.7.5
- CVE-2017-7729On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.7.5
- CVE-2017-7730iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.7.5