CVE-2018-17915
Summary
| CVE | CVE-2018-17915 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-10 15:29:00 UTC |
| Updated | 2019-10-09 23:37:00 UTC |
| Description | All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xiongmaitech | Xmeye P2p Cloud Server | - | All | All | All |
| Application | Xiongmaitech | Xmeye P2p Cloud Server | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.