Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r65w-5jgv-h7gj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability.

An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability.

EPSS

Процентиль: 22%
0.00072
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.8
nvd
больше 7 лет назад

An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability.

EPSS

Процентиль: 22%
0.00072
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20