Unauthenticated Access to Site Security Key in OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules

Unauthenticated Access to Site Security Key in OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules

CVE-2014-2361 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.

Learn more about our Physical Security Assessment.