Vulnerability Details CVE-2021-20990
In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdown, a reboot or a reboot into recovery mode.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 7.8
Products affected by CVE-2021-20990
-
cpe:2.3:h:fibaro:home_center_2:-
-
cpe:2.3:h:fibaro:home_center_lite:-
-
cpe:2.3:o:fibaro:home_center_2_firmware:-
-
cpe:2.3:o:fibaro:home_center_2_firmware:4.540
-
cpe:2.3:o:fibaro:home_center_2_firmware:4.600
-
cpe:2.3:o:fibaro:home_center_lite_firmware:-
-
cpe:2.3:o:fibaro:home_center_lite_firmware:4.540
-
cpe:2.3:o:fibaro:home_center_lite_firmware:4.550