VulnerabilityModified
CVE-2015-8269
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.
HIGH 7.5EPSS 2.29%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- fisher-price/smart toy bear
- Source
- cret@cert.org
References
- https://community.rapid7.com/community/infosec/blog/2016/02/02/security-vulnerabilities-within-fisher-price-smart-toy-hereo-gps-platform
- https://www.kb.cert.org/vuls/id/719736US Government Resource
- https://www.kb.cert.org/vuls/id/GWAN-A6LPPWUS Government Resource
- https://community.rapid7.com/community/infosec/blog/2016/02/02/security-vulnerabilities-within-fisher-price-smart-toy-hereo-gps-platform
- https://www.kb.cert.org/vuls/id/719736US Government Resource
- https://www.kb.cert.org/vuls/id/GWAN-A6LPPWUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.