VulnerabilityModified
CVE-2020-23512
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.
CRITICAL 9.8EPSS 2.29%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- vr cam/p1 firmware
- Source
- cve@mitre.org
References
- https://www.iotpentest.com/2020/05/vr-360-camera-general-wlak.htmlExploit, Third Party Advisory
- https://www.iotpentest.com/2020/05/vr-360-camera-general-wlak.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.