PT-2025-9925 · Smartwares · Smartwares Cameras

Marcin Wyczechowski

+2

·

Publicado

2025-03-06

·

Atualizado

2025-03-07

·

CVE-2024-13894

CVSS v4.0

5.9

Média

VetorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Smartwares cameras versions up to 3.3.0
Description The issue allows for path traversal attacks, enabling access to sensitive information by manipulating file paths. When connected to a mobile app, affected devices open port 10000, allowing users to download pictures by providing specific file paths. However, the directories accessible to users are not properly restricted, facilitating the path traversal attacks. The vendor has not responded to reports, and the patching status is unknown.
Recommendations For versions up to 3.3.0, as a temporary workaround, consider restricting access to port 10000 when not in use, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-02435
CVE-2024-13894

Produtos afetados

Smartwares Cameras