CVE Published: 03/12/2024 |
CVE Updated: 03/12/2024 |
CVE Year: 2024 Source: rapid7 |
Vendor: Lorex |
Product: 2K Indoor Wi-Fi Security Camera Status : PUBLISHED
CVE-2024-52545 Description
An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L