MEDIUM · 6.5

CVE-2021-3793

An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access adminis...

Vulnerability Description

An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
BinatoneglobalHalo\+ Camera Firmware< 03.50.14
BinatoneglobalHalo\+ Camera-
BinatoneglobalComfort 85 Connect Firmware< 03.40.02
BinatoneglobalComfort 85 Connect-
BinatoneglobalMbp3855 Firmware< 03.40.00
BinatoneglobalMbp3855-
BinatoneglobalFocus 68 Firmware-
BinatoneglobalFocus 68v100
BinatoneglobalFocus 72R Firmware< 03.40.00
BinatoneglobalFocus 72Rv100
BinatoneglobalCn28 Firmware-
BinatoneglobalCn28-
BinatoneglobalCn50 Firmware-
BinatoneglobalCn50-
BinatoneglobalComfort 40 Firmware-
BinatoneglobalComfort 40-
BinatoneglobalComfort 50 Connect Firmware-
BinatoneglobalComfort 50 Connect-
BinatoneglobalMbp4855 Firmware-
BinatoneglobalMbp4855-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3793?

CVE-2021-3793 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access adminis...

How severe is CVE-2021-3793?

CVE-2021-3793 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3793?

Check the references section above for vendor advisories and patch information. Affected products include: Binatoneglobal Halo\+ Camera Firmware, Binatoneglobal Halo\+ Camera, Binatoneglobal Comfort 85 Connect Firmware, Binatoneglobal Comfort 85 Connect, Binatoneglobal Mbp3855 Firmware.