CVE-2021-3791
Last modified
CVE-2021-3791 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Binatoneglobal | Halo\+ Camera Firmware | < 03.50.14 |
| Binatoneglobal | Comfort 85 Connect Firmware | < 03.40.02 |
| Binatoneglobal | Mbp3855 Firmware | < 03.40.00 |
| Binatoneglobal | Focus 68 Firmware | All versions |
| Binatoneglobal | Focus 72r Firmware | < 03.40.00 |
| Binatoneglobal | Cn28 Firmware | All versions |
| Binatoneglobal | Cn50 Firmware | All versions |
| Binatoneglobal | Comfort 40 Firmware | All versions |
| Binatoneglobal | Comfort 50 Connect Firmware | All versions |
| Binatoneglobal | Mbp4855 Firmware | All versions |
| Binatoneglobal | Mbp3667 Firmware | All versions |
| Binatoneglobal | Mbp669 Connect Firmware | All versions |
| Binatoneglobal | Lux 64 Firmware | All versions |
| Binatoneglobal | Lux 65 Firmware | All versions |
| Binatoneglobal | Connect View 65 Firmware | All versions |
| Binatoneglobal | Lux 85 Connect Firmware | All versions |
| Binatoneglobal | Ease44 Firmware | All versions |
| Binatoneglobal | Connect 20 Firmware | All versions |
| Binatoneglobal | Mbp6855 Firmware | All versions |
| Binatoneglobal | Cn40 Firmware | All versions |
| Binatoneglobal | Cn75 Firmware | All versions |
References
- https://binatoneglobal.com/security-advisory/Vendor Advisory
- https://binatoneglobal.com/security-advisory/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3791?
How severe is CVE-2021-3791?
How do I fix CVE-2021-3791?
Are you affected by CVE-2021-3791?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
