• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Friday, June 13, 2025
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise

January 12, 2024
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


A vulnerability has been found in a preferred Bosch sensible thermostat, permitting potential attackers to ship instructions to the system and exchange its firmware, in accordance with Bitdefender.

The vulnerability impacts the Wi-Fi microcontroller that acts as a community gateway for the thermostat’s logic microcontroller.

The Bosch sensible thermostat merchandise BCC101, BCC102 and BCC50, from model 4.13.20 till v4.13.33 are affected. The vulnerability (CVE-2023-49722) has been given a ‘Excessive’ severity rating.

Homeowners of the thermostat have been urged to replace their thermostats to v4.13.33 to patch the flaw.

Bitdefender revealed it first knowledgeable Bosch of the vulnerability on August 29, 2023. After being triaged and confirmed, Bosch deployed a repair in v4.13.33 in October 2023.

The vulnerability was then publicly disclosed on January 9, 2024.

How the Vulnerability Works

The researchers stated they found that the STM chip in one of many thermostat’s two microcontrollers depends on the WiFi chip within the different microcontroller to speak with the web.

The WiFi chip additionally listens on TCP port 8899 on the LAN and can mirror any message acquired on that port on to the principle microcontroller.

Because of this malicious instructions may be despatched to the thermostat which can’t be distinguished from real ones despatched by the cloud server, reminiscent of writing an replace to the system.

To start the malicious replace process, the researchers ship the ‘system/replace’ command on port 8899 to tell the system {that a} new replace is on the market.

The system will then ask the cloud server for particulars in regards to the replace, which responds with an error code as a result of no replace is on the market.

Nonetheless, the system will settle for a solid response containing the replace particulars: the URL the place the firmware will probably be downloaded from, the scale and MD5 checksum of the firmware file, and the model of the brand new firmware, which should be greater than the present one.

If all of the circumstances match, together with an internet-accessible URL, the thermostat asks the cloud server to obtain the firmware and ship it via the websocket.

The cloud will then carry out the improve as soon as it has acquired the file, inflicting the system to be completely compromised.

The patch replace revealed by Bosch works by closing the port 8899.

Recommendation for IoT Machine Homeowners

Bitdefender set out the next recommendation for shoppers to scale back the danger of their residence IoT units being exploited by cyber menace actors:

  • Arrange a devoted community for IoT units to isolate them as a lot as attainable from the native community
  • Use free instruments to scan for related units on the community, and determine and spotlight weak ones
  • Test for newer firmware and replace units as quickly as the seller releases new variations



Source link

Tags: BoschcompromiseputsRiskSmartThermostatsvulnerability
Next Post
Best Cloud Based Project Management Software & Tools for 2024

Best Cloud Based Project Management Software & Tools for 2024

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Beirut, LB
14°
Cloudy / Wind
05:4017:50 EET
Feels like: 13°C
Wind: 34km/h SW
Humidity: 65%
Pressure: 1012.19mbar
UV index: 0
FriSatSun
14°C / 9°C
16°C / 11°C
18°C / 12°C
powered by Weather Atlas

Recent News

PS5 Finally Has More Monthly Players Than PS4

PS5 Finally Has More Monthly Players Than PS4

June 13, 2025
Batman Begins 20 Years Later: Ranking Nolan Trilogy Characters

Batman Begins 20 Years Later: Ranking Nolan Trilogy Characters

June 13, 2025
Apple Games and the future of iOS gaming

Apple Games and the future of iOS gaming

June 13, 2025
Life Uncut’s Brittany Hockley and Ben Siegrist’s 00 wedding cake disaster

Life Uncut’s Brittany Hockley and Ben Siegrist’s $1000 wedding cake disaster

June 13, 2025
AFL round 14: Hawks vs Crows live updates — blog, scores and stats from Launceston

AFL round 14: Hawks vs Crows live updates — blog, scores and stats from Launceston

June 13, 2025
Celtic given permission to speak to 16-goal star who is available for £2m

Celtic given permission to speak to 16-goal star who is available for £2m

June 13, 2025
Trump administration throws wrench into  billion broadband rollout

Trump administration throws wrench into $42 billion broadband rollout

June 13, 2025
Virtuelle Maschine als Tarnkappe – Sophos News

Virtuelle Maschine als Tarnkappe – Sophos News

June 13, 2025
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Popular
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

PS5 Finally Has More Monthly Players Than PS4

PS5 Finally Has More Monthly Players Than PS4

June 13, 2025
Batman Begins 20 Years Later: Ranking Nolan Trilogy Characters

Batman Begins 20 Years Later: Ranking Nolan Trilogy Characters

June 13, 2025
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.