Vulnerabilities (CVE)

Filtered by vendor Micasaverde Subscribe
Filtered by product Veralite Firmware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-4862 1 Micasaverde 2 Veralite, Veralite Firmware 2020-02-04 5.5 MEDIUM 8.1 HIGH
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.
CVE-2013-4863 1 Micasaverde 2 Veralite, Veralite Firmware 2020-02-04 9.0 HIGH 8.8 HIGH
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a RunLua action in a request to port_49451/upnp/control/hag.