Show filters
117 Total Results
Displaying 1-10 of 117
Sort by:
Attacker Value
Unknown

CVE-2022-4003

Disclosure Date: July 31, 2024 (last updated August 14, 2024)
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.
Attacker Value
Unknown

CVE-2022-4002

Disclosure Date: July 31, 2024 (last updated August 14, 2024)
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
Attacker Value
Unknown

CVE-2022-4001

Disclosure Date: July 31, 2024 (last updated August 01, 2024)
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
0
Attacker Value
Unknown

CVE-2024-38285

Disclosure Date: June 13, 2024 (last updated June 14, 2024)
Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.
0
Attacker Value
Unknown

CVE-2024-38284

Disclosure Date: June 13, 2024 (last updated June 14, 2024)
Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.
0
Attacker Value
Unknown

CVE-2024-38283

Disclosure Date: June 13, 2024 (last updated June 14, 2024)
Sensitive customer information is stored in the device without encryption.
0
Attacker Value
Unknown

CVE-2024-38282

Disclosure Date: June 13, 2024 (last updated June 14, 2024)
Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or shutdown the camera requiring a physical reboot of the system.
0
Attacker Value
Unknown

CVE-2024-38281

Disclosure Date: June 13, 2024 (last updated October 04, 2024)
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
Attacker Value
Unknown

CVE-2024-38280

Disclosure Date: June 13, 2024 (last updated October 04, 2024)
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
Attacker Value
Unknown

CVE-2024-38279

Disclosure Date: June 13, 2024 (last updated October 04, 2024)
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.