Vulnerabilities > CVE-2021-27953 - NULL Pointer Dereference vulnerability in Ecobee Ecobee3 Lite Firmware 4.5.81.200

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
ecobee
CWE-476

Summary

A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request.

Vulnerable Configurations

Part Description Count
OS
Ecobee
1
Hardware
Ecobee
1

Common Weakness Enumeration (CWE)