CVE-2013-4863
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a RunLua action in a request to port_49451/upnp/control/hag.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.18% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- micasaverde/veralite firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/122654/MiCasaVerde-VeraLite-1.5.408-Traversal-Authorization-CSRF-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/27286Exploit, Third Party Advisory, VDB Entry
- https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-019.txtExploit
- http://packetstormsecurity.com/files/122654/MiCasaVerde-VeraLite-1.5.408-Traversal-Authorization-CSRF-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/27286Exploit, Third Party Advisory, VDB Entry
- https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-019.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.