Impact
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights, giving them direct unauthorized command over the lighting system. The vulnerability was fixed in firmware version 1.77.2071318010.
Affected Systems
The flaw exists in Signify Philips Hue Bridge Pro firmware that embeds a Mosquitto MQTT broker service. All units running vulnerable firmware without updates that disable or secure the broker are vulnerable. The vulnerability does not affect other Signify products listed.
Risk and Exploitability
CVSS 6.9 indicates moderate severity. The vulnerability is not listed in KEV and the EPSS score is < 1%, but it relies on local network access and the broker is exposed on all interfaces. Based on the description, the likely attack vector is an attacker with network access to the bridge’s MQTT port, allowing them to read data and control lights. Because the Bridge is commonly on home or office networks and the MQTT port is well known, the attack vector is realistic and the impact can be significant if an attacker gains local network access.
OpenCVE Enrichment