ZeroHour

CVE-2020-24396

CVSS 3.1
7.5 high
EPSS
2%p78
Published
()
Modified
Description

homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.

Vendors
hom.ee
Products
brain cube core
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.