Key Information Vulnerability Overview - CVSS v4.8.5 - Threat Level: Low attack complexity - Vendor: Dreame Technology - Affected Devices: DreameHome and MOVAhome mobile applications - Vulnerability Type: Improper certificate validation Risk Assessment - Successful exploitation of this vulnerability could lead to unauthorized information disclosure. Technical Details - Affected Products: - DreameHome iOS application version 2.3.4 and earlier - DreameHome Android application version 2.1.6.3 and earlier - MOVAhome iOS application version 1.2.3 and earlier - Vulnerability Description: A TLS vulnerability exists in the mobile applications used to manage connected devices. The phone applications accept self-signed certificates, which, when establishing TLS communication, could enable a man-in-the-middle attack. Captured communications may include user credentials and sensitive session tokens. - CVE Number: CVE-2022-8393 - CVSS v3.1 Base Score: 7.3 Background - Critical Infrastructure Sector: Communications - Deployment Country/Region: Vietnam - Company Headquarters Location: China Researchers - Dennis Giese reported this vulnerability to CISA. Mitigations - Dreame Technology did not respond to CISA’s coordination request. Contact Dreame Technology for additional information. - CISA recommends implementing basic defensive measures, such as minimizing network exposure, placing control system networks and remote devices behind firewalls, and isolating them from business networks. - Use virtual private network (VPN) authentication to ensure connections are only made to trusted devices. Update History - August 7, 2023: Initial release