CERT-In Vulnerability Note
CIVN-2024-0329
Cleartext Storage of Sensitive Information Vulnerability in Philips Lighting Devices
Original Issue Date:October 25, 2024
Severity Rating: HIGH
Systems Affected
- Philips Smart Wi-Fi LED Batten 24-Watt - all firmware versions prior to 1.33.1
- Philips Smart Wi-Fi LED T Beamer 20-Watt - all firmware versions prior to 1.33.1
- Philips Smart Bulb 9,10,12-Watt - all firmware versions prior to 1.33.1
- Philips Smart T-Bulb 10,12-Watt - all firmware versions prior to 1.33.1
Overview
A vulnerability has been reported in Philips lighting devices which could allow an attacker with physical access the device to obtain sensitive information on the targeted devices.
Description
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi credentials stored on the vulnerable device.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the Wi-Fi network to which vulnerable device is connected.
Credit
This vulnerability is reported by Shravan Singh, Amey Chavekar. Vishal Giri and Dr. Faruk Kazi from CoE- CNDS Lab, VJTI Mumbai, India
Solution
- Upgrade Philips Smart Wi-Fi LED Batten 24-Watt, LED T Beamer 20-Watt, Smart Bulb 9,10,12-Watt and Smart T-Bulb 10,12-Watt to version 1.33.1
Vendor Information
Signify Innovations India
https://in.shop.lighting.philips.com/
References
Signify Innovations India
https://in.shop.lighting.philips.com/
CVE Name
CVE-2024-9991
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|