Executive brief
The Vivint Sky Control Panel is a central hub used to manage home security and automation systems. A vulnerability in its web interface allows unauthorized individuals to remotely arm or disarm the security alarm and change critical system settings. This could lead to a complete compromise of physical home security and unauthorized access to the premises.
Technical details
A vulnerability classified as improper access control (CWE-284) exists in the web-enabled interface of the Vivint Sky Control Panel firmware version 1.1.1.9926. The flaw allows a remote, unauthenticated attacker to interact with the device's management functions over the network. By sending crafted requests to the web interface, an attacker can bypass authentication to toggle the alarm state and modify security configurations. This provides full control over the security appliance without requiring physical access or valid credentials.
Affected products
- Vivint Sky Control Panel 1.1.1.9926
Timeline
- 2017-01-23: advisory: NVD published the vulnerability details.