Show plain JSON{"id": "CVE-2021-27953", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 6.9, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2021-08-03T15:15:08.297", "references": [{"url": "https://www.l9group.com/advisories/remote-denial-of-service-of-ecobee3-lite", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.l9group.com/advisories/remote-denial-of-service-of-ecobee3-lite", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-476"}]}], "descriptions": [{"lang": "en", "value": "A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request."}, {"lang": "es", "value": "Se presenta una vulnerabilidad de desrefencia de puntero NULL en el dispositivo ecobee3 lite versi\u00f3n 4.5.81.200, en el proceso de configuraci\u00f3n de HomeKit Wireless Access Control. Un actor de la amenaza puede explotar esta vulnerabilidad para causar una denegaci\u00f3n de servicio, forzando el dispositivo a reiniciar por medio de una petici\u00f3n HTTP dise\u00f1ada"}], "lastModified": "2024-11-21T05:58:54.573", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:ecobee:ecobee3_lite_firmware:4.5.81.200:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDA0D6FC-A69F-4F21-9F49-EEA1FA924B8A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:ecobee:ecobee3_lite:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "665F647B-440F-4059-B7E7-70245C66B028"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org"}