Vulnerability Description
An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the camera to record or take a picture after bypassing authentication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xiaoyi | Yi M1 Mirrorless Camera Firmware | 3.2-cn |
| Xiaoyi | Yi M1 Mirrorless Camera | - |
References
- https://www.cnvd.org.cn/flaw/show/CNVD-2019-23494Third Party Advisory
- https://www.cnvd.org.cn/flaw/show/CNVD-2019-23494Third Party Advisory
FAQ
What is CVE-2019-13953?
CVE-2019-13953 is a vulnerability with a CVSS score of 8.8 (HIGH). An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trig...
How severe is CVE-2019-13953?
CVE-2019-13953 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13953?
Check the references section above for vendor advisories and patch information. Affected products include: Xiaoyi Yi M1 Mirrorless Camera Firmware, Xiaoyi Yi M1 Mirrorless Camera.