Required CVE Record Information
Description
Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass intended access restrictions via a modified update.
References 1 Total
- kb.cert.org: VU#573848 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 1 Total
- kb.cert.org: VU#573848 third-party-advisoryx_transferred