Описание
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server.
Ссылки
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.0.794 (включая)
Одновременно
cpe:2.3:o:cognitoys:stemosaur_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cognitoys:stemosaur:-:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00123
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-327
Связанные уязвимости
CVSS3: 5.9
github
больше 3 лет назад
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server.
EPSS
Процентиль: 32%
0.00123
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-327