Vulnerabilities > CVE-2018-3934 - Unspecified vulnerability in Yitechnology YI Home Camera Firmware 1.8.7.0D
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger this vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Talos
id | TALOS-2018-0601 |
last seen | 2019-05-29 |
published | 2018-10-31 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0601 |
title | Yi Technology Home Camera 27US nonce reuse authentication bypass vulnerability |