API ThreatStats’ Post

View organization page for API ThreatStats, graphic

1,008 followers

🚨High Risk Vulnerability Alert! 🚨: CVE-2022-32510 An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2. CVSSv3.1 Base Score: 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) #nuki #apisecurity #owasp https://lnkd.in/dFDPgyfp

To view or add a comment, sign in

Explore topics