Vulnerability Description
The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Floureon | Sp012 | - |
Related Weaknesses (CWE)
References
- http://neolex-security.fr/article/obtenir-un-shell-root-par-les-ports-uart-sur-uBroken LinkThird Party Advisory
- https://neolex-security.fr/blog/8/ExploitThird Party Advisory
- https://neolex-security.fr/blog/7/Third Party Advisory
- http://neolex-security.fr/article/obtenir-un-shell-root-par-les-ports-uart-sur-uBroken LinkThird Party Advisory
- https://neolex-security.fr/blog/8/ExploitThird Party Advisory
FAQ
What is CVE-2018-20342?
CVE-2018-20342 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privi...
How severe is CVE-2018-20342?
CVE-2018-20342 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20342?
Check the references section above for vendor advisories and patch information. Affected products include: Floureon Sp012.