CVE-2024-5633 Vulnerability Details

  /     /     /  

CVE-2024-5633 Metadata Quick Info

CVE Published: 09/07/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: CERT-PL | Vendor: Longse Technology | Product: LBH30FE200W
Status : PUBLISHED

CVE-2024-5633 Description

Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located in the same local network to an undocumented binary service CoolView on one of the ports.  An attacker with a knowledge of the available commands is able to perform read/write operations on the device\'s memory, which might result in e.g. bypassing telnet login and obtaining full access to the device.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-912
CWE Name: CWE-912 Hidden Functionality
Source: Longse Technology

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-115
CAPEC Description: CAPEC-115 Authentication Bypass


Source: NVD (National Vulnerability Database).