Meari IoT Cloud Platform OpenAPI Service
Summary
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to authorization flaws, allowing authenticated users to manipulate device configurations they do not own and access sensitive information without proper authorization. Successful exploitation could lead to unauthorized actions such as altering device settings or triggering unintended behaviors.
IFF Assessment
The identified vulnerabilities allow attackers to gain unauthorized access and control over devices, posing a significant risk to system integrity and data confidentiality.
Severity
The CVSS score of 7.7 indicates a High severity vulnerability. This is based on the 'Missing Authorization' vulnerability type (CWE-862), which allows attackers to perform actions on devices they do not own, leading to potential manipulation of device configurations and access to sensitive data.
Defender Context
Defenders should be aware of this vulnerability affecting Meari IoT Cloud Platform OpenAPI Service, particularly concerning the manipulation of device configurations and unauthorized access to sensitive data. Given that Meari did not respond to CISA's coordination attempts and has no fix planned, users are advised to exercise extreme caution and consider alternative solutions or enhanced monitoring for affected devices.