5

CVE-2014-1900

Exploit

Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote attackers to bypass authentication and obtain sensitive information via a leading "/./" in a request to en/account/accedit.asp.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Y-camYcb002 Firmware Version4.30
   Y-camYcb002
Y-camYcb004 Firmware Version4.30
   Y-camYcb004
Y-camYcw003 Firmware Version4.30
   Y-camYcw003
Y-camYcb001 Firmware Version4.30
   Y-camYcb001
Y-camYcblhd5 Firmware Version4.30
   Y-camYcblhd5
Y-camYcbl03 Firmware Version4.30
Y-camYcblb3 Firmware Version4.30
Y-camYcw001 Firmware Version4.30
   Y-camYcw001
Y-camYck004 Firmware Version4.30
   Y-camYck004
Y-camYck003 Firmware Version4.30
   Y-camYck003
Y-camYcw004 Firmware Version4.30
Y-camYcb003 Firmware Version4.30
   Y-camYcb003
Y-camYceb03 Firmware Version4.30
   Y-camYceb03
Y-camYcw002 Firmware Version4.30
   Y-camYcw002
Y-camYck002 Firmware Version4.30
   Y-camYck002
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.468
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.