CVE Vulnerabilities

CVE-2021-3791

Insertion of Sensitive Information into Log File

Published: Nov 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Halo+_camera_firmware Binatoneglobal * 03.50.14 (excluding)

Potential Mitigations

References