All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06 | Third Party Advisory US Government Resource |
Configurations
History
No history.
Information
Published : 2018-10-10 15:29
Updated : 2019-10-09 23:37
NVD link : CVE-2018-17919
Mitre link : CVE-2018-17919
JSON object : View
Products Affected
xiongmaitech
- xmeye_p2p_cloud_server
CWE
CWE-798
Use of Hard-coded Credentials