Vulnerabilities > CVE-2014-2361 - Local Security Bypass vulnerability in Oleumtech products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode. <a href="http://cwe.mitre.org/data/definitions/320.html" target="_blank">CWE-320: CWE-320: Key Management Errors</a>
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Hardware | 2 |