Логотип exploitDog
bind:CVE-2024-56897
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-56897

Количество 2

Количество 2

nvd логотип

CVE-2024-56897

12 месяцев назад

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v8m2-qqpw-r35m

12 месяцев назад

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-56897

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-v8m2-qqpw-r35m

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

CVSS3: 9.8
0%
Низкий
12 месяцев назад

Уязвимостей на страницу