8.8
CVE-2021-3577
- EPSS 86.43%
- Veröffentlicht 12.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:53
- Quelle psirt@lenovo.com
- CVE-Watchlists
- Unerledigt
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Binatoneglobal ≫ Halo+ Camera Firmware Version < 03.50.14
Binatoneglobal ≫ Comfort 85 Connect Firmware Version < 03.40.02
Binatoneglobal ≫ Mbp3855 Firmware Version < 03.40.00
Binatoneglobal ≫ Focus 68 Firmware Version-
Binatoneglobal ≫ Focus 68 Firmware Version-
Binatoneglobal ≫ Focus 72r Firmware Version < 03.40.00
Binatoneglobal ≫ Focus 72r Firmware Version < 03.40.00
Binatoneglobal ≫ Cn28 Firmware Version-
Binatoneglobal ≫ Cn50 Firmware Version-
Binatoneglobal ≫ Comfort 40 Firmware Version-
Binatoneglobal ≫ Comfort 50 Connect Firmware Version-
Binatoneglobal ≫ Mbp4855 Firmware Version-
Binatoneglobal ≫ Mbp3667 Firmware Version-
Binatoneglobal ≫ Mbp669 Connect Firmware Version-
Binatoneglobal ≫ Lux 64 Firmware Version-
Binatoneglobal ≫ Lux 65 Firmware Version-
Binatoneglobal ≫ Connect View 65 Firmware Version-
Binatoneglobal ≫ Lux 85 Connect Firmware Version-
Binatoneglobal ≫ Ease44 Firmware Version-
Binatoneglobal ≫ Connect 20 Firmware Version-
Binatoneglobal ≫ Mbp6855 Firmware Version-
Binatoneglobal ≫ Cn40 Firmware Version-
Binatoneglobal ≫ Cn75 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 86.43% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
| psirt@lenovo.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.