Description
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7593 | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo). |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2018-47 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-09-17T02:10:50.517Z
Reserved: 2018-08-22T00:00:00.000Z
Link: CVE-2018-15723
No data.
Status : Modified
Published: 2018-12-20T21:29:00.777
Modified: 2024-11-21T03:51:20.690
Link: CVE-2018-15723
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD