PT-2024-36792 · Longse · Longse Model Lbh30Fe200W

Adam Zambrzycki

·

Published

2024-07-09

·

Updated

2024-08-01

·

CVE-2024-5633

CVSS v4.0

7.5

High

VectorAV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Longse model LBH30FE200W cameras (affected versions not specified)
Description The issue allows an attacker in the same local network to access an undocumented binary service CoolView on one of the ports, providing unrestricted access. With knowledge of available commands, an attacker can perform read/write operations on the device's memory. This could result in bypassing telnet login and obtaining full access to the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Hidden Functionality

Weakness Enumeration

Related Identifiers

CVE-2024-5633

Affected Products

Longse Model Lbh30Fe200W