Описание
Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.4.7 (исключая)
Одновременно
cpe:2.3:o:amazon:ring_video_doorbell_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amazon:ring_video_doorbell:-:*:*:*:*:*:*:*
EPSS
Процентиль: 23%
0.00077
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-327
Связанные уязвимости
CVSS3: 9.1
github
больше 3 лет назад
Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.
EPSS
Процентиль: 23%
0.00077
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-327