570
VMScore

CVE-2018-17915

Published: 10/10/2018 Updated: 09/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an malicious user to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xiongmaitech xmeye p2p cloud server -

Exploits

XMeye P2P Cloud used with Xiongmai IP Cameras, NVRs and DVRs suffer from predictable Cloud IDs, default admin password, and various other issues that can result in remote code execution ...

Mailing Lists

SEC Consult also published a blog post regarding the identified security issues with further background information: Blog: rsec-consultcom/xmeye SEC Consult Vulnerability Lab Security Advisory < 20181009-0 > ======================================================================= title: Remote Code Execution via XMey ...