SB2018101105 - Multiple vulnerabilities in Hangzhou Xiongmai Technology XMeye P2P Cloud Server
Published: October 11, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2018-17917)
CWE-ID: CWE-341 - Predictable from Observable State
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to unspecified flaw. A remote attacker can use MAC addresses, enumerate potential Cloud IDs and use it to discover and connect to valid devices using one of the supported apps.
2) Security restrictions bypass (CVE-ID: CVE-2018-17919)
CWE-ID: CWE-912 - Hidden Functionality (Backdoor)
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to unspecified flaw. A remote attacker can use an undocumented user account “default” with its default password to login to XMeye and access/view video streams.
3) Privilege escalation (CVE-ID: CVE-2018-17915)
CWE-ID: CWE-311 - Missing Encryption of Sensitive Data
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain elevated privileges.
The vulnerability exists due to missing encryption of sensitive data. A remote attacker can eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.
Remediation
Install update from vendor's website.