Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgpj-cx57-3c5q

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.

The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.

EPSS

Процентиль: 21%
0.00067
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.

EPSS

Процентиль: 21%
0.00067
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-319