Release date:
Updated on:
Affected Systems:
Belkin Wemo Home Automation
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65633
CVE (CAN) ID: CVE-2013-6951
Belkin Wemo Home Automation devices is a series of Home Appliance Remote Control Products.
The Belkin Wemo Home Automation device does not have a local certificate library to verify the integrity of the SSL connection. Attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application.
<* Source: Mike Davis
Link: http://www.kb.cert.org/vuls/id/656302
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Belkin
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.belkin.com/us/Products/home-automation/c/wemo-home-automation