Overview
All firmware versions of Qolsys IQ Panel contain hard-coded cryptographic keys, do not validate signatures during software updates, and use a vulnerable version of Android OS.
Description
Qolsys IQ Panel is an Android OS-based touch screen controller for home automation devices and functions. All firmware versions contain the following vulnerabilities. CWE-321: Use of Hard-coded Cryptographic Key - CVE-2015-6032 |
Impact
A remote, unauthenticated attacker may be able to inject malicious firmware or software updates that will be accepted as valid by affected devices. It may be possible to leverage known vulnerabilities affecting Android OS 2.2.1 compromise affected devices. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem. The vendor has indicated that they will release QOL 1.5.1 to address these issues in November 2015, but until then, users should consider the following workaround. |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Temporal | 6.8 | E:POC/RL:U/RC:C |
Environmental | 5.1 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Roman Faynberg from Carve Systems for reporting this vulnerability.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2015-6032, CVE-2015-6033 |
Date Public: | 2015-10-29 |
Date First Published: | 2015-10-29 |
Date Last Updated: | 2015-10-29 16:14 UTC |
Document Revision: | 23 |