CVE-2021-24046
MEDIUMCVSS 5.3/10EPSS 0.70%
Last modified
CVE-2021-24046 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ray-Ban | Stories Rw4003 65582v 48-23 Firmware | < 2107460.6810.0 |
| Ray-Ban | Stories Rw4002 601\/71 50-22 Firmware | < 2107460.6810.0 |
| Ray-Ban | Stories Rw4005 656013 51-20 Firmware | < 2107460.6810.0 |
| Ray-Ban | Stories Rw4005 6563m3 51-20 Firmware | < 2107460.6810.0. |
References
- https://www.facebook.com/security/advisories/cve-2021-24046Vendor Advisory
- https://www.facebook.com/security/advisories/cve-2021-24046Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-24046?
A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.
How severe is CVE-2021-24046?
CVE-2021-24046 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.70% probability of exploitation in the next 30 days.
How do I fix CVE-2021-24046?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-24040Due to use of unsafe YAML deserialization logic, an attacker…9.8
- CVE-2021-24041A missing bounds check in image blurring code prior to Whats…9.8
- CVE-2021-24042The calling logic for WhatsApp for Android prior to v2.21.23…9.8
- CVE-2021-24043A missing bound check in RTCP flag parsing code prior to Wha…9.1
- CVE-2021-24044By passing invalid javascript code where await and yield wer…9.8
- CVE-2021-24045A type confusion vulnerability could be triggered when resol…9.8
- CVE-2021-2405Vulnerability in the Oracle Engineering product of Oracle E-…8.1
- CVE-2021-2406Vulnerability in the Oracle Collaborative Planning product o…8.1
- CVE-2021-24066Microsoft SharePoint Remote Code Execution Vulnerability8.8
- CVE-2021-24067Microsoft Excel Remote Code Execution Vulnerability7.8
- CVE-2021-24068Microsoft Excel Remote Code Execution Vulnerability7.8
- CVE-2021-24069Microsoft Excel Remote Code Execution Vulnerability7.8
Are you affected by CVE-2021-24046?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
