CVE-2024-13892
CVE-2024-13892
Título es
CVE-2024-13892
Jue, 06/03/2025 – 14:15
Tipo
CWE-77
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-13892
Descripción en
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injection.
During the initialization process, a user has to use a mobile app to provide devices with Access Point credentials. This input is not properly sanitized, what allows for command injection.
The vendor has not replied to reports, so the patching status remains unknown. Newer firmware versions might be vulnerable as well.
06/03/2025
06/03/2025
Vector CVSS:4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Gravedad 4.0
7.70
Gravedad 4.0 txt
HIGH
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://cert.pl/en/posts/2025/03/CVE-2024-13892/
https://www.smartwares.eu/en-gb/smartwares-cip-37210at-indoor-wi-fi-camera-cip–37210at
Enviar en el boletín
Off
