CVE-2017-8403

UnknownEPSS 0.81%

Last modified

CVE-2017-8403 is a vulnerability of currently unknown severity. 360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. EPSS estimates a 0.81% chance of exploitation in the next 30 days.

Description

360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can use the 360fly Android or iOS application, or the BlueZ gatttool program.

Metrics

EPSS Probability
0.81%

52.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
360fly4k Camera Firmware2.1.4

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-8403?
360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can use the 360fly Android or iOS application, or the BlueZ gatttool program.
How severe is CVE-2017-8403?
Severity scoring for CVE-2017-8403 is pending analysis. The EPSS model estimates a 0.81% probability of exploitation in the next 30 days.
How do I fix CVE-2017-8403?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-8403?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST