ZeroHour

CVE-2023-31411

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
Description

A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

Vendors
sick
Products
sick eventcam app
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.