CVE Vulnerabilities

CVE-2021-3787

Plaintext Storage of a Password

Published: Nov 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

Name Vendor Start Version End Version
Halo+_camera_firmware Binatoneglobal * 03.50.14 (excluding)

Potential Mitigations

References