IoT’s Cloud Risk on Display with Flaws in Fuze Collaboration Platform
ID: a53c1ddd-7889-542b-898a-f2d553e5cbea
STIX ID: report--a53c1ddd-7889-542b-898a-f2d553e5cbea
Feed Name: Security Ledger
Threat Score
Rapid7 disclosed flaws in Fuze’s web-based handset administration portal that allowed attackers to enumerate device-specific administrative URLs (derived from MAC addresses) and obtain phone numbers, email addresses, parent account names and admin links. The issues were compounded by use of HTTP (no HTTPS) and lack of rate limiting for admin logins; Fuze deployed rate limiting to mitigate the issue and reported no known exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
