CVE Published: 03/12/2024 |
CVE Updated: 03/12/2024 |
CVE Year: 2024 Source: rapid7 |
Vendor: Lorex |
Product: 2K Indoor Wi-Fi Security Camera Status : PUBLISHED
CVE-2024-52548 Description
An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
Metrics
CVSS Version: 3.1 |
Base Score: 6.7 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* LOW Privileges Required (PR)* HIGH User Interaction (UI)* NONE Scope (S)* UNCHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-345 CWE Name: CWE-345 Insufficient Verification of Data Authenticity Source: Lorex
Common Attack Pattern Enumeration and Classification (CAPEC)