CVE-2021-3793
Last modified
CVE-2021-3793 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Binatoneglobal | Halo\+ Camera Firmware | < 03.50.14 |
| Binatoneglobal | Comfort 85 Connect Firmware | < 03.40.02 |
| Binatoneglobal | Mbp3855 Firmware | < 03.40.00 |
| Binatoneglobal | Focus 68 Firmware | All versions |
| Binatoneglobal | Focus 72r Firmware | < 03.40.00 |
| Binatoneglobal | Cn28 Firmware | All versions |
| Binatoneglobal | Cn50 Firmware | All versions |
| Binatoneglobal | Comfort 40 Firmware | All versions |
| Binatoneglobal | Comfort 50 Connect Firmware | All versions |
| Binatoneglobal | Mbp4855 Firmware | All versions |
| Binatoneglobal | Mbp3667 Firmware | All versions |
| Binatoneglobal | Mbp669 Connect Firmware | All versions |
| Binatoneglobal | Lux 64 Firmware | All versions |
| Binatoneglobal | Lux 65 Firmware | All versions |
| Binatoneglobal | Connect View 65 Firmware | All versions |
| Binatoneglobal | Lux 85 Connect Firmware | All versions |
| Binatoneglobal | Ease44 Firmware | All versions |
| Binatoneglobal | Connect 20 Firmware | All versions |
| Binatoneglobal | Mbp6855 Firmware | All versions |
| Binatoneglobal | Cn40 Firmware | All versions |
| Binatoneglobal | Cn75 Firmware | All versions |
References
- https://binatoneglobal.com/security-advisory/Vendor Advisory
- https://binatoneglobal.com/security-advisory/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3793?
How severe is CVE-2021-3793?
How do I fix CVE-2021-3793?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-37924Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37925Zoho ManageEngine ADManager Plus version 7110 and prior has …9.8
- CVE-2021-37926Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37927Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37928Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37929Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37930Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37931Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37933An LDAP injection vulnerability in /account/login in Huntflo…7.5
- CVE-2021-37934Due to insufficient server-side login-attempt limit enforcem…9.8
- CVE-2021-37935An information disclosure vulnerability in the login page of…7.5
- CVE-2021-37936It was discovered that Kibana was not sanitizing document fi…5.4
Are you affected by CVE-2021-3793?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
