The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2023-04-04T16:54:06.709Z

Updated: 2024-08-02T05:57:25.083Z

Reserved: 2023-03-30T20:04:29.870Z

Link: CVE-2023-1751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-04-04T17:15:07.227

Modified: 2023-11-07T04:04:49.510

Link: CVE-2023-1751

cve-icon Redhat

No data.