CRITICAL
Authentication Bypass by Primary Weakness in Kiloview P1/P2 devices
Published Jul 2, 2024
9.8
CRITICALCVSS 3.1
EPSS 0.42%
Description
The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.
Affected products
-
Affected
- ≥ All, ≤ 4.8.2605
No data.
-
Affected
- 0
-
Affected
- 0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Kiloview | P1 4g Video Encoder Firmware | unknown | Affected
|
| Kiloview | P2 4g Video Encoder Firmware | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NCSC-NL
Published Jul 2, 2024
Updated Aug 2, 2024
Reserved Sep 5, 2023
Link CVE-2023-41920
CISA Vulnrichment
Updated Jul 2, 2024
Red Hat
No data
GitHub
No data