Vulnerabilities > CVE-2018-3920 - Unspecified vulnerability in Yitechnology YI Home Camera Firmware 1.8.7.0D
Attack vector
PHYSICAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH low complexity
yitechnology
Summary
An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Talos
id | TALOS-2018-0584 |
last seen | 2019-05-29 |
published | 2018-10-31 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0584 |
title | Yi Technology Home Camera 27US Firmware 7z CRC Collision Vulnerability |