CVE-2024-46041

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 7, 2024
CWE ID 294

Summary

CVE-2024-46041 is a newly identified vulnerability affecting the IoT Haat Smart Plug IH-IN-16A-S version 5.16.1. This issue enables an attacker to bypass the authentication process through capture-replay attacks. An unauthorized user can intercept and reuse valid authentication credentials to gain unauthorized access to the smart plug, potentially leading to control over connected devices and networks. The vulnerability poses a significant risk to IoT security, as authentication bypass can facilitate further unauthorized activities. Users are advised to update their smart plug firmware to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share