vendor:
Quantum
by:
David Castro
7.5
CVSS
HIGH
Login bypass and data leak
287
CWE
Product Name: Quantum
Affected Version From: 2.0
Affected Version To: 3.2.243
Patch Exists: YES
Related CWE: CVE-2018-8880
CPE: a:lutron:quantum:2.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Login bypass and data leak – Lutron Quantum 2.0 – 3.2.243 firmware
A vulnerability in Lutron Quantum 2.0 - 3.2.243 firmware allows an attacker to bypass authentication and leak device and network information. The vulnerability exists due to insufficient authentication checks when handling requests to the deviceIP page. An attacker can exploit this vulnerability by sending a specially crafted request to the deviceIP page. Successful exploitation of this vulnerability could allow an attacker to bypass authentication and leak device and network information.
Mitigation:
Upgrade to the latest version of Lutron Quantum 2.0 - 3.2.243 firmware.