CVE-2024-56897
Last modified
CVE-2024-56897 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yitechnology | Yi Car Dashcam Firmware | 3.88 |
References
- https://geochen.medium.com/cve-2024-56897-yi-car-dashcam-39304a4b21b4Exploit, Third Party Advisory
- https://github.com/geo-chen/YI-Smart-Dashcam/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-56897?
How severe is CVE-2024-56897?
How do I fix CVE-2024-56897?
Are you affected by CVE-2024-56897?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
