Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lightify Home CRITICAL 9.8
CVE-2016-5053

OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.

Fix: after 1.6.1
Fix from $2,300 2017-04-10
Lightify Home HIGH 7.5
CVE-2016-5051

OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.

Fix: after 1.6.1
Fix from $1,950 2017-04-10
Lightify Home HIGH 7.5
CVE-2016-5052

OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.

Fix: after 1.6.1
Fix from $1,950 2017-04-10
Lightify Home HIGH 7.5
CVE-2016-5054

OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.

Fix: after 1.6.1
Fix from $1,950 2017-04-10
Lightify Pro HIGH 7.5
CVE-2016-5056

OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.

No fix yet
Fix from $1,950 2017-04-10
Lightify Pro HIGH 7.5
CVE-2016-5057

OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.

No fix yet
Fix from $1,950 2017-04-10
Lightify Pro HIGH 7.5
CVE-2016-5058

OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.

No fix yet
Fix from $1,950 2017-04-10
Lightify Pro MEDIUM 6.5
CVE-2016-5059

OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile…

No fix yet
Fix from $1,600 2017-04-10
Lightify Pro MEDIUM 6.1
CVE-2016-5055

OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.

No fix yet
Fix from $1,600 2017-04-10