| ID |
CVE-2018-3910
|
| Sažetak |
An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability. Alternatively, an attacker can convince a user to connect their camera to this SSID. |
| Reference |
|
| CVSS |
| Base: | 5.4 |
| Impact: | 6.4 |
| Exploitability: | 5.5 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| ADJACENT_NETWORK |
MEDIUM |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| PARTIAL |
PARTIAL |
PARTIAL |
|
| CVSS vektor |
AV:A/AC:M/Au:N/C:P/I:P/A:P |
| Zadnje važnije ažuriranje |
02-02-2023 - 02:06 |
| Objavljeno |
01-11-2018 - 15:29 |