Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9ww-7rv4-vqfq

Опубликовано: 10 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

EPSS

Процентиль: 66%
0.00519
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

CVSS3: 7.7
fstec
около 4 лет назад

Уязвимость функции get_aes_key_info_by_packetid() микропрограммного обеспечения систем видеонаблюдения Anker Eufy Homebase, позволяющая нарушителю обойти процедуру аутентификации

EPSS

Процентиль: 66%
0.00519
Низкий

7.5 High

CVSS3

Дефекты

CWE-287