PT-2017-12344 · Disney · Circle With Disney
Publicado
2017-11-07
·
Atualizado
2022-04-19
·
CVE-2017-12083
CVSS v3.1
5.8
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Circle with Disney version 2.0.1
Description
An information disclosure issue exists in the apid daemon, where a specially crafted set of packets can cause the device to dump internal database strings into an HTTP response. This can be triggered by an attacker with network connectivity to the Internet.
Recommendations
For Circle with Disney version 2.0.1, consider restricting access to the apid daemon until a patch is available. As a temporary workaround, limit network connectivity to minimize the risk of exploitation.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Circle With Disney