CVE Vulnerabilities

CVE-2018-17917

Predictable from Observable State

Published: Oct 10, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.

Weakness

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

Affected Software

Name Vendor Start Version End Version
Xmeye_p2p_cloud_server Xiongmaitech * *

Potential Mitigations

References