CyberRota Analysis
AI-GeneratedThe Signify Philips Hue Bridge Pro firmware is vulnerable due to the embedded Mosquitto MQTT broker (v2.0.22), which allows anonymous access and listens on all network interfaces without firewall restrictions. This vulnerability enables attackers on the same network to read device data and control connected lighting systems. Organizations utilizing Philips Hue Bridge Pro should prioritize addressing this issue to mitigate potential unauthorized access and control of their smart lighting infrastructure.
Original NVD Description
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010.