CVE-2023-3104 Vulnerability Details
/
/
/
CVE-2023-3104 Metadata Quick Info
CVE Published: 22/11/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023
Source: INCIBE |
Vendor: Unitree Robotics |
Product: A1
Status : PUBLISHED
CVE-2023-3104 Description
Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any form of authentication.
Metrics
CVSS Version: 3.1 |
Base Score: 5.7 MEDIUM
Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
l➤ Exploitability Metrics:
Attack Vector (AV)* ADJACENT_NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* LOW
User Interaction (UI)* NONE
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* HIGH
Integrity Impact (I)* NONE
Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-306
CWE Name: CWE-306 Missing Authentication for Critical Function
Source: Unitree Robotics
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-216
CAPEC Description: CAPEC-216 Communication Channel Manipulation
Source: NVD (National Vulnerability Database).