CVE Vulnerabilities

CVE-2024-31799

Cleartext Transmission of Sensitive Information

Published: Aug 15, 2024 | Modified: Aug 16, 2024
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Information Disclosure in GNCCs GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Gncc_c2_firmware Gncchome - (including) - (including)

Potential Mitigations

References