PT-2023-9141 · Owlet · Owlet Cam

Alexandru Lazar

+1

·

Publicado

2023-10-23

·

Atualizado

2024-07-08

·

CVE-2023-6321

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Owlet Cam versions v1 and v2
Description A command injection vulnerability exists in the IOCTL that manages OTA updates, allowing a specially crafted command to lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability, potentially enabling remote execution of arbitrary commands and privilege escalation.
Recommendations For Owlet Cam version v1, upgrade the affected components immediately to mitigate the risk. For Owlet Cam version v2, upgrade the affected components immediately to mitigate the risk. As a temporary workaround, consider restricting access to the IOCTL handler that manages OTA updates until a patch is available.

Exploit

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-04018
CVE-2023-6321

Produtos afetados

Owlet Cam