Improper Authentication in ilbo App for Android and ilbo App for iOS - CVE-2020-5532

 

Improper Authentication in ilbo App for Android and ilbo App for iOS - CVE-2020-5532

Published: February 14, 2020


Vulnerability identifier: #VU25347
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5532
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to insufficient authentication. A remote authenticated attacker on the local network can view the images which were recorded by the other user's ilbo device.


Affected software

ilbo App for Android
ilbo App for iOS

How to mitigate CVE-2020-5532

Install updates from vendor's website.

ilbo App for Android - update to 1.1.8
ilbo App for iOS - update to 1.2.0

External References

Related Security Bulletins