MEDIUM · 6.5

CVE-2021-3791

An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file ...

Vulnerability Description

An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
BinatoneglobalHalo\+ Camera Firmware< 03.50.14
BinatoneglobalHalo\+ Camera-
BinatoneglobalComfort 85 Connect Firmware< 03.40.02
BinatoneglobalComfort 85 Connect-
BinatoneglobalMbp3855 Firmware< 03.40.00
BinatoneglobalMbp3855-
BinatoneglobalFocus 68 Firmware-
BinatoneglobalFocus 68v100
BinatoneglobalFocus 72R Firmware< 03.40.00
BinatoneglobalFocus 72Rv100
BinatoneglobalCn28 Firmware-
BinatoneglobalCn28-
BinatoneglobalCn50 Firmware-
BinatoneglobalCn50-
BinatoneglobalComfort 40 Firmware-
BinatoneglobalComfort 40-
BinatoneglobalComfort 50 Connect Firmware-
BinatoneglobalComfort 50 Connect-
BinatoneglobalMbp4855 Firmware-
BinatoneglobalMbp4855-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3791?

CVE-2021-3791 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file ...

How severe is CVE-2021-3791?

CVE-2021-3791 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3791?

Check the references section above for vendor advisories and patch information. Affected products include: Binatoneglobal Halo\+ Camera Firmware, Binatoneglobal Halo\+ Camera, Binatoneglobal Comfort 85 Connect Firmware, Binatoneglobal Comfort 85 Connect, Binatoneglobal Mbp3855 Firmware.