8.8

CVE-2021-3577

An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BinatoneglobalHalo+ Camera Firmware Version < 03.50.14
   BinatoneglobalHalo+ Camera Version-
BinatoneglobalMbp3855 Firmware Version < 03.40.00
   BinatoneglobalMbp3855 Version-
BinatoneglobalFocus 68 Firmware Version-
   BinatoneglobalFocus 68 Versionv100
BinatoneglobalFocus 68 Firmware Version-
   BinatoneglobalFocus 68 Versionv200
BinatoneglobalFocus 72r Firmware Version < 03.40.00
   BinatoneglobalFocus 72r Versionv100
BinatoneglobalFocus 72r Firmware Version < 03.40.00
   BinatoneglobalFocus 72r Versionv200
BinatoneglobalCn28 Firmware Version-
   BinatoneglobalCn28 Version-
BinatoneglobalCn50 Firmware Version-
   BinatoneglobalCn50 Version-
BinatoneglobalMbp4855 Firmware Version-
   BinatoneglobalMbp4855 Version-
BinatoneglobalMbp3667 Firmware Version-
   BinatoneglobalMbp3667 Version-
BinatoneglobalLux 64 Firmware Version-
   BinatoneglobalLux 64 Version-
BinatoneglobalLux 65 Firmware Version-
   BinatoneglobalLux 65 Version-
BinatoneglobalEase44 Firmware Version-
   BinatoneglobalEase44 Version-
BinatoneglobalMbp6855 Firmware Version-
   BinatoneglobalMbp6855 Version-
BinatoneglobalCn40 Firmware Version-
   BinatoneglobalCn40 Version-
BinatoneglobalCn75 Firmware Version-
   BinatoneglobalCn75 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 86.43% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.8 6.5 6.4
AV:A/AC:L/Au:N/C:P/I:P/A:P
psirt@lenovo.com 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.