5.3
CVSSv3

CVE-2018-17917

Published: 10/10/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an malicious user to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xiongmaitech xmeye p2p cloud server

Exploits

XMeye P2P Cloud used with Xiongmai IP Cameras, NVRs and DVRs suffer from predictable Cloud IDs, default admin password, and various other issues that can result in remote code execution ...

Mailing Lists

SEC Consult also published a blog post regarding the identified security issues with further background information: Blog: rsec-consultcom/xmeye SEC Consult Vulnerability Lab Security Advisory < 20181009-0 > ======================================================================= title: Remote Code Execution via XMey ...