SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3791

An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID…

MEDIUM 6.5EPSS 0.42%

Does this matter?

Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.

Description

An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.42% probability · 36th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
binatoneglobal/halo\+ camera firmware · binatoneglobal/comfort 85 connect firmware · binatoneglobal/mbp3855 firmware · binatoneglobal/focus 68 firmware · binatoneglobal/focus 72r firmware · binatoneglobal/cn28 firmware · binatoneglobal/cn50 firmware · binatoneglobal/comfort 40 firmware · binatoneglobal/comfort 50 connect firmware · binatoneglobal/mbp4855 firmware · binatoneglobal/mbp3667 firmware · binatoneglobal/mbp669 connect firmware · binatoneglobal/lux 64 firmware · binatoneglobal/lux 65 firmware · binatoneglobal/connect view 65 firmware · binatoneglobal/lux 85 connect firmware · binatoneglobal/ease44 firmware · binatoneglobal/connect 20 firmware · binatoneglobal/mbp6855 firmware · binatoneglobal/cn40 firmware · +1 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.