The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security. No credentials or special permissions are required, and access can be gained remotely over the network.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://shinxyy.github.io/blogs/CVE_2024_51362.html |
History
Wed, 06 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lsc Smart Connect
Lsc Smart Connect indoor Camera Firmware |
|
Weaknesses | CWE-306 | |
CPEs | cpe:2.3:o:lsc_smart_connect:indoor_camera_firmware:7.6.32:*:*:*:*:*:*:* | |
Vendors & Products |
Lsc Smart Connect
Lsc Smart Connect indoor Camera Firmware |
|
Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security. No credentials or special permissions are required, and access can be gained remotely over the network. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-05T00:00:00
Updated: 2024-11-06T19:27:32.513Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-51362
Vulnrichment
Updated: 2024-11-06T19:27:27.462Z
NVD
Status : Awaiting Analysis
Published: 2024-11-05T17:15:07.383
Modified: 2024-11-06T20:35:35.750
Link: CVE-2024-51362
Redhat
No data.