Vulnerability Description
permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ztehome | C520V21 Firmware | <= 2.1.14 |
| Ztehome | C520V21 | - |
Related Weaknesses (CWE)
References
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1011842Vendor Advisory
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1011842Vendor Advisory
FAQ
What is CVE-2019-3423?
CVE-2019-3423 is a vulnerability with a CVSS score of 5.3 (MEDIUM). permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other una...
How severe is CVE-2019-3423?
CVE-2019-3423 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3423?
Check the references section above for vendor advisories and patch information. Affected products include: Ztehome C520V21 Firmware, Ztehome C520V21.