SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3793

An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information…

MEDIUM 5.3EPSS 0.69%

Does this matter?

Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.

Description

An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.69% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-424
Affected
binatoneglobal/halo\+ camera firmware · binatoneglobal/comfort 85 connect firmware · binatoneglobal/mbp3855 firmware · binatoneglobal/focus 68 firmware · binatoneglobal/focus 72r firmware · binatoneglobal/cn28 firmware · binatoneglobal/cn50 firmware · binatoneglobal/comfort 40 firmware · binatoneglobal/comfort 50 connect firmware · binatoneglobal/mbp4855 firmware · binatoneglobal/mbp3667 firmware · binatoneglobal/mbp669 connect firmware · binatoneglobal/lux 64 firmware · binatoneglobal/lux 65 firmware · binatoneglobal/connect view 65 firmware · binatoneglobal/lux 85 connect firmware · binatoneglobal/ease44 firmware · binatoneglobal/connect 20 firmware · binatoneglobal/mbp6855 firmware · binatoneglobal/cn40 firmware · +1 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.