5.7

CVE-2018-3891

Exploit

An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this vulnerability.

Data is provided by the National Vulnerability Database (NVD)
YitechnologyYi Home Camera Firmware Version1.8.7.0d
   YitechnologyYi Home Camera Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.13% 0.334
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
talos-cna@cisco.com 5.7 0.9 4.7
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L