Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7q6m-9v39-q68q

Опубликовано: 18 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained access through other means, to list and download recorded videos, as well as access live video streams without proper authentication.

On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained access through other means, to list and download recorded videos, as well as access live video streams without proper authentication.

EPSS

Процентиль: 31%
0.0012
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained access through other means, to list and download recorded videos, as well as access live video streams without proper authentication.

EPSS

Процентиль: 31%
0.0012
Низкий

7.5 High

CVSS3

Дефекты

CWE-306