SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human interaction.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-296-02 | third party advisory us government resource |
http://www.securityfocus.com/bid/105729 | vdb entry third party advisory |