New ring vulnerability (new firmware with patch available)

SecuritySeeker

Pulling my weight
Joined
Oct 5, 2018
Messages
266
Reaction score
156
Location
Netherlands
From bulguard.com: One Ring to rule them all, and in darkness bind them

Feb 27,2019 | Posted by Or Cyngiser, Cyber Security Researcher

Executive summary:

Plaintext transmission of audio/video footage to the Ring application allows for arbitrary surveillance and injection of counterfeit traffic, effectively compromising home security.
...
...
Important note: Ring has patched this vulnerability in version 3.4.7 of the ring app (Without notifying users in the patch notes!). Please make sure to upgrade to a newer version ASAP as the affected versions are still backward compatible and vulnerable.
#SayNoToTheCloud :)
 
Top