PT-2020-15015 · Megvii · Megvii Koala
Joey Costoya
+4
·
Published
2020-08-14
·
Updated
2020-08-21
·
CVE-2020-17475
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MEGVII Koala version 2.9.1-c3s
Description
The issue is related to a lack of authentication in network relays, allowing attackers to send packet data to UDP port 5000 and grant physical access to unauthorized individuals.
Recommendations
For MEGVII Koala version 2.9.1-c3s, consider restricting access to UDP port 5000 as a temporary workaround until a patch is available.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Megvii Koala