Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2013-6951

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Belkin WeMo Home Automation是美国贝尔金(Belkin)公司的家庭自动化系列产品。 Belkin WeMo Home Automation设备3949之前的版本中存在安全漏洞,该漏洞源于设备没有本地证书来验证SSL连接的完整性。攻击者可借助任意X.509证书利用该漏洞实施中间人攻击,欺骗SSL服务器。

AI Predicted 7.5 Difficulty: Easy EPSS 0.62% · P47
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2013-6951

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary X.509 certificate.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Belkin WeMo Home Automation 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Belkin WeMo Home Automation是美国贝尔金(Belkin)公司的家庭自动化系列产品。 Belkin WeMo Home Automation设备3949之前的版本中存在安全漏洞,该漏洞源于设备没有本地证书来验证SSL连接的完整性。攻击者可借助任意X.509证书利用该漏洞实施中间人攻击,欺骗SSL服务器。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2013-6951

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-6951

登录查看更多情报信息。

Vendor Advisories for CVE-2013-6951 (1)

Other References for CVE-2013-6951 (1)

Same Patch Batch · n/a · 2014-02-22 · 24 CVEs total

CVE-2014-0721 Cisco Unified SIP Phone 3905 未授权访问漏洞
CVE-2014-1266 Apple iOS ‘SSLVerifySignedServerKeyExchange’函数输入验证漏洞
CVE-2014-0861 IBM Cognos Business Intelligence 跨站脚本漏洞
CVE-2014-0854 IBM Cognos Business Intelligence XML外部实体攻击漏洞
CVE-2014-0819 Autodesk AutoCAD 不可信搜索路径漏洞
CVE-2014-0818 Autodesk AutoCAD 安全漏洞
CVE-2014-0811 Blackboard Vista/CE 跨站脚本漏洞
CVE-2014-0739 Cisco Adaptive Security Appliances Phone Proxy 竞争条件漏洞
CVE-2014-0738 Cisco ASA Software Phone Proxy 安全漏洞
CVE-2014-0737 Cisco Unified IP Phone 7960G 安全漏洞
CVE-2014-0731 Cisco Unified Communications Manager 安全漏洞
CVE-2014-0730 Cisco Unified Computing System 提权漏洞
CVE-2013-6732 IBM Cognos Business Intelligence 跨站脚本漏洞
CVE-2014-0720 Cisco IPS Software 拒绝服务漏洞
CVE-2014-0719 Cisco IPS Software control-plane MainApp 拒绝服务漏洞
CVE-2014-0718 Cisco IPS Software produce-verbose-alert 拒绝服务漏洞
CVE-2014-0710 Cisco Firewall Services Module Cut-Through Proxy 竞争条件漏洞
CVE-2014-0709 Cisco UCS Director 安全漏洞
CVE-2013-6952 Belkin WeMo Home Automation 安全漏洞
CVE-2013-6950 Belkin WeMo Home Automation 信息泄露漏洞

Showing top 20 of 24 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-6951

No comments yet


Leave a comment