CVE-2018-13115
Summary
| CVE | CVE-2018-13115 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-22 20:29:00 UTC |
| Updated | 2019-01-29 16:09:00 UTC |
| Description | Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Keruigroup | Ypc99 | - | All | All | All |
| Hardware | Keruigroup | Ypc99 | - | All | All | All |
| Operating System | Keruigroup | Ypc99 Firmware | All | All | All | All |
| Operating System | Keruigroup | Ypc99 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities on Kerui Endoscope Camera – Utku Sen - Blog – computer security, programming | MISC | utkusen.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.