PT-2019-13021 · Shenzhen Cylan · Clever Dog Smart Camera
Publicado
2019-06-20
·
Atualizado
2021-07-21
·
CVE-2019-12919
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Shenzhen Cylan Clever Dog Smart Camera versions DOG-2W and DOG-2W-V4
Description
The issue allows an attacker on the local network to have unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera enables anyone to view or download the video archive recorded and saved on the external memory card attached to the device.
Recommendations
For versions DOG-2W and DOG-2W-V4, restrict access to the HTTP service on port 8000 to prevent unauthorized access to the internal SD card. Consider disabling the HTTP web server until a patch is available to mitigate the risk of exploitation.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Clever Dog Smart Camera