Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16225

Опубликовано: 18 сент. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 6.1
EPSS Низкий

Описание

The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:qbeecam:qbee_multi-sensor_camera_firmware:*:*:*:*:*:*:*:*
Версия до 4.16.4 (включая)
cpe:2.3:h:qbeecam:qbee_multi-sensor_camera:-:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:qbeecam:qbeecam:*:*:*:*:*:android:*:*
Версия до 1.0.5 (включая)
cpe:2.3:a:swisscom:swisscom_home_app:*:*:*:*:*:android:*:*
Версия до 10.7.2 (включая)

EPSS

Процентиль: 21%
0.00067
Низкий

6.5 Medium

CVSS3

6.1 Medium

CVSS2

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.

EPSS

Процентиль: 21%
0.00067
Низкий

6.5 Medium

CVSS3

6.1 Medium

CVSS2

Дефекты

CWE-319