Description
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
Published: 2023-07-25
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade IQ Wifi 6 firmware to version 2.0.2. The firmware update will be pushed to all available devices in the field. The firmware update can also be manually loaded by applying the patch tag “iqwifi2.0.2” on the device after navigating to its firmware update page.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44204 An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
History

Wed, 23 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Johnsoncontrols Iq Wifi 6 Iq Wifi 6 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2024-10-23T19:01:43.727Z

Reserved: 2023-07-07T19:02:52.585Z

Link: CVE-2023-3548

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:56.452Z

cve-icon NVD

Status : Modified

Published: 2023-07-25T14:15:11.123

Modified: 2024-11-21T08:17:30.860

Link: CVE-2023-3548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses