CVE-2015-4400
Summary
| CVE | CVE-2015-4400 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-06 16:29:00 UTC |
| Updated | 2018-03-13 19:13:00 UTC |
| Description | Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless network configuration by pressing the set up button and leveraging an API in the GainSpan Wi-Fi module. |
Risk And Classification
Problem Types: CWE-255
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ring | Ring | - | All | All | All |
| Hardware | Ring | Ring | - | All | All | All |
| Operating System | Ring | Ring Firmware | - | All | All | All |
| Operating System | Ring | Ring Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2015-4400 : Backdoorbot, Network Configuration Leak on a Connected Doorbell | MISC | blog.fortinet.com | Broken Link |
| Fortinet Discovers DoorBot Network Configuration Leak Vulnerability | FortiGuard | MISC | fortiguard.com | Third Party Advisory |
| Steal your Wi-Fi key from your doorbell? IoT WTF! | Pen Test Partners | MISC | www.pentestpartners.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.