igloohome Smart Lock Mobile Application
A vulnerability in the igloohome Smart Lock Mobile Application (Android 3.2.3) allows an unauthorized actor to access backend services. This could enable access to sensitive functionality and potentially compromise the security of igloohome smart locks deployed globally. The vendor has released a fix, and CISA recommends minimizing network exposure and using secure remote access methods.
A vulnerability has been identified in the igloohome Smart Lock Mobile Application (Android 3.2.3). This vulnerability, classified as an Inclusion of Sensitive Information in Source Code (CWE-540), allows an unauthorized actor to access backend services that were not adequately protected by authentication controls. The affected product is the igloohome Smart Lock Mobile Application, and it is deployed worldwide. The vulnerability was reported by Vincent C. of CodeVispera and has been acknowledged by CISA.
Affected Products:
- igloohome Smart Lock Mobile Application
- igloohome
Remediation:
- Vendor fix: igloohome has enhanced access control mechanisms on backend services to ensure that only properly authenticated and authorized requests can interact with sensitive functionality. No user interaction is needed.
CISA recommends that users take defensive measures to minimize the risk of exploitation. These include:
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.