CVE-2018-17917
Summary
| CVE | CVE-2018-17917 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-10 15:29:00 UTC |
| Updated | 2019-10-09 23:37:00 UTC |
| Description | All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xiongmaitech | Xmeye P2p Cloud Server | All | All | All | All |
| Application | Xiongmaitech | Xmeye P2p Cloud Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.