#VU15694 Authorization bypass in Yi Home Camera - CVE-2018-3934

 

#VU15694 Authorization bypass in Yi Home Camera - CVE-2018-3934

Published: November 2, 2018


Vulnerability identifier: #VU15694
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-3934
CWE-ID: CWE-592
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Yi Home Camera
Software vendor:
YI Technology

Description

The vulnerability allows a remote attacker to bypass authentication on the target system.

The vulnerability exists due to a logic flaw in the firmware update functionality during insufficient sanitization of user-supplied data. A remote attacker can sniff network traffic and send a set of UDP packets to bypass authentication and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Remediation

Update to the latest version.

External links