Lifesize Audit

Lifesize security audit

Lifesize Icon 450

Firmware Audited: Build date: Mon Aug 28 07:08:05 CDT 2017 Build host: ausbuildlifesizecodecicon02 (127.0.1.1) Build location: http://artifacts.lifesize.com/artifactory/lifesize.icon.production/lifesize.icon.production.master.sequoia.full-3.4.0.2268.tar.gz Build version: LS_RM3_3.4.0 (2268) Build type: PRODUCTION Build target: sequoia SVN; SVN%

Findings:

Lifesize Screen Sharing And Scheduling - Chrome Plugin

Version: Chrome Web Store release as of 09/0/17

Findings:

  • Full access to browser history and *.lifesize.com domains
  • Jquery 2.1.4
  • NPM dependencies are locked using only fuzzy versions and no hash locking. Dependency attacks are on the table if no other mitigations are present.